The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
Minimum safe version
6.4.10
Update to 6.4.10 or later to address 37 fixable vulnerabilities
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar
The Plus Addons for Elementor <= 6.3.15 - Authenticated (Author+) Stored Cross-Site Scripting via SVG
CVE-2025-55712
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-49076
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
CVE-2024-11829
CVE-2024-53823
CVE-2024-10365
CVE-2024-8913
CVE-2024-43977
CVE-2024-43932
CVE-2024-5583
CVE-2024-6575
CVE-2024-5763
CVE-2024-4482
CVE-2024-4983
CVE-2024-35709
CVE-2024-2784
CVE-2024-4484
CVE-2024-3718
CVE-2024-4485
CVE-2024-0445
CVE-2024-2785
CVE-2024-34373
CVE-2024-3199
CVE-2024-3197
CVE-2024-2203
CVE-2024-2210
CVE-2024-1419
CVE-2024-23511
CVE-2021-4332
CVE-2021-4331
WordPress The Plus Addons for Elementor Page Builder Lite plugin <= 2.0.5 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2021-24266