CVE-2024-13362
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits
Minimum safe version
2.1.4
Update to 2.1.4 or later to address 34 fixable vulnerabilities
Master Addons For Elementor <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text'
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits <= 2.1.3 - Authenticated (Author+) Stored Cross-Site Scripting
CVE-2025-63053
CVE-2025-63055
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fancyBox
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Master Addons <= 2.0.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
Master Addons <= 2.0.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
WordPress Master Addons for Elementor Plugin <= 2.0.6.7 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-52387
CVE-2024-6282
CVE-2024-38710
CVE-2024-35688
CVE-2024-35702
CVE-2024-5542
CVE-2024-5382
CVE-2024-35660
CVE-2024-3134
CVE-2024-4580
CVE-2024-4265
CVE-2024-33595
CVE-2024-29911
CVE-2024-2139
Master Addons for Elementor < 2.0.4 - Contributor+ Stored XSS
WordPress Master Addons for Elementor Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)
Master Addons for Elementor <= 2.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting
CVE-2023-40679
WordPress Master Addons for Elementor Plugin < 2.0.3 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Master Addons for Elementor plugin < 1.8.5 - Sensitive Information Disclosure vulnerability
WordPress Master Addons for Elementor plugin < 1.8.5 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-0327