Medium 6.5
2026-03-13< 1.4.2
CVE-2026-32429
Minimum safe version
1.4.2
Update to 1.4.2 or later to address 10 fixable vulnerabilities
CVE-2026-32429
Magical Addons For Elementor <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
CVE-2024-54212
CVE-2024-10352
CVE-2024-51665
CVE-2024-38730
CVE-2024-38681
WordPress Magical Addons For Elementor Plugin <= 1.1.39 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-34547
WordPress Magical Addons For Elementor Plugin <= 1.1.37 is vulnerable to Cross Site Scripting (XSS)