Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 - Missing Authorization
Essential Addons for Elementor – Popular Elementor Templates & Widgets
Minimum safe version
6.6.0
Update to 6.6.0 or later to address 62 fixable vulnerabilities
Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure
Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget
CVE-2026-23543
Essential Addons for Elementor <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-13977
CVE-2025-64352
Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'
Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget
CVE-2025-24752
CVE-2025-39590
CVE-2025-39589
CVE-2024-56063
CVE-2024-8978
CVE-2024-8961
CVE-2024-8979
CVE-2021-4446
CVE-2021-4447
CVE-2024-8742
CVE-2024-8440
CVE-2024-7092
CVE-2024-39649
CVE-2024-5189
CVE-2024-5188
CVE-2024-5073
CVE-2024-34764
CVE-2024-4624
CVE-2024-4449
CVE-2024-4275
CVE-2024-4448
CVE-2024-4156
CVE-2024-4003
CVE-2024-3728
CVE-2024-3733
CVE-2024-3333
CVE-2024-2974
CVE-2024-3018
CVE-2024-2650
CVE-2024-2623
CVE-2024-1536
CVE-2024-1537
CVE-2024-1172
CVE-2024-1276
CVE-2024-1236
CVE-2024-1171
CVE-2024-0954
CVE-2024-0585
CVE-2024-0586
CVE-2023-7044
CVE-2023-41955
Essential Addons for Elementor <= 5.8.8 - Authenticated (Contributor+) Privilege Escalation
CVE-2023-3779
CVE-2023-32243
Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation
Essential Addons for Elementor <= 4.6.4 - Missing Authorization
WordPress Essential Addons for Elementor plugin <= 4.5.3 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2021-24255
CVE-2022-0320
CVE-2022-0683