WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Addon Elements For Elementor Page Builder?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Addon Elements For Elementor Page Builder — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: addon-elements-for-elementor-page-builder
  • 90000+ instalaciones activas

addonselementorelementor addonelementor widgetelements

Estado de mantenimiento

  • Requiere PHP: 7.0+

Vulnerabilidades conocidas

28 CVEs conocidos registrados para Addon Elements For Elementor Page Builder. Reportadas entre 2020 y 2025.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-12537 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.14.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 1.14.4 1.14.4 2025-12-13
CVE-2026-28131 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.14.5 Inserción de información sensible en los datos enviados Media 6,5 < 1.14.5 1.14.5 2025-08-28
CVE-2024-13215 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.14 Exposición de información personal privada a un actor no autorizado Media 4,3 < 1.14 1.14 2025-01-14
CVE-2024-8902 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.9 Exposición de información sensible a un actor no autorizado Media 4,3 < 1.13.9 1.13.9 2024-10-11
CVE-2024-47361 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.7 Falta de control de autorización Media 6,5 < 1.13.7 1.13.7 2024-09-30
CVE-2024-47366 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 1.13.7 1.13.7 2024-09-30
CVE-2024-4401 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13.6 1.13.6 2024-08-29
CVE-2024-7122 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13.7 1.13.7 2024-08-29

CVE-2025-12537

The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.14.3. This is due to insufficient input sanitization and output escaping on multiple widget parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts via multiple widget parameters in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-28131

The Addon Elements for Elementor (formerly Elementor Addon Elements) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-13215

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-8902

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-47361

The Elementor Addon Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_refresh_insta_cache() function in versions up to, and including, 1.13.6. This makes it possible for authenticated attackers, with contributor-level access and above, to refresh cache for posts they do not have access to.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-47366

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-4401

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-7122

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 30 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-4570 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13.6 1.13.6 2024-06-26
CVE-2024-4569 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13.6 1.13.6 2024-06-26
CVE-2024-2092 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13.4 1.13.4 2024-06-11
CVE-2024-3743 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13.4 1.13.4 2024-04-29
CVE-2024-30422 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 1.13.2 1.13.2 2024-03-28
CVE-2024-2091 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,6 < 1.13.2 1.13.2 2024-03-27
CVE-2024-2792 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13.3 1.13.3 2024-03-27
CVE-2024-29107 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.12.11 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 1.12.11 1.12.11 2024-03-15
CVE-2024-1358 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,5 < 1.13 1.13 2024-02-21
CVE-2024-1422 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13 1.13 2024-02-21
CVE-2024-1393 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13 1.13 2024-02-21
CVE-2024-1392 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13 1.13 2024-02-21
CVE-2024-1391 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.13 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.13 1.13 2024-02-21
CVE-2024-0834 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.12.12 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.12.12 1.12.12 2024-02-05
CVE-2023-4689 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.12.8 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 1.12.8 1.12.8 2023-11-15
CVE-2023-4690 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.12.8 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 1.12.8 1.12.8 2023-11-15
CVE-2023-4723 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.12.8 Falta de control de autorización Media 5,3 < 1.12.8 1.12.8 2023-11-15
CVE-2023-5381 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.12.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 1.12.8 1.12.8 2023-11-15
CVE-2023-33999 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.12 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 1.12 1.12 2023-07-18
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.14 Falta de control de autorización Media 6,3 < 1.11.14 1.11.14 2022-03-04
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.14 Desconocido < 1.11.14 1.11.14 2022-02-28
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.14 Desconocido < 1.11.14 1.11.14 2022-02-28
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.8 Desconocido < 1.11.8 1.11.8 2021-07-20
CVE-2021-24259 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.11.2 1.11.2 2021-04-13
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.2 Desconocido < 1.11.2 1.11.2 2021-04-13
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.6.4 Desconocido < 1.6.4 1.6.4 2020-09-09
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.6.4 Desconocido < 1.6.4 1.6.4 2020-09-08
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.14 Desconocido < 1.11.14 1.11.14
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.8 Desconocido < 1.11.8 1.11.8
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.6.4 Desconocido < 1.6.4 1.6.4

CVE-2024-4570

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4569

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2092

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3743

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group, Shape Separator, Content Switcher, Info Circle and Timeline widgets in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-30422

Update the WordPress Elementor Addon Elements plugin to the latest available version (at least 1.13.2). Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Addon Elements Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.13.2. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-2091

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.13.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2792

Update the WordPress Elementor Addon Elements plugin to the latest available version (at least 1.13.3). wesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Addon Elements Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.13.3. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-29107

Update the WordPress Elementor Addon Elements plugin to the latest available version (at least 1.12.11). Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Addon Elements Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.12.11. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1358

Update the WordPress Elementor Addon Elements plugin to the latest available version (at least 1.13). wesley (wcraft) discovered and reported this Local File Inclusion vulnerability in WordPress Elementor Addon Elements Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover depending on the configuration. This vulnerability has been fixed in version 1.13. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1422

Update the WordPress Elementor Addon Elements plugin to the latest available version (at least 1.13). Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Addon Elements Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.13. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1393

Update the WordPress Elementor Addon Elements plugin to the latest available version (at least 1.13). Nikolas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Addon Elements Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.13. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1392

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button1_icon' attribute of the Dual Button widget in all versions up to, and including, 1.12.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-1391

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eae_custom_overlay_switcher’ attribute of the Thumbnail Slider widget in all versions up to, and including, 1.12.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-0834

Update the WordPress Elementor Addon Elements plugin to the latest available version (at least 1.12.12). Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Addon Elements Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.12.12. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-4689

The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7. This is due to missing or incorrect nonce validation on the eae_save_elements function. This makes it possible for unauthenticated attackers to enable/disable elementor addon elements via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-4690

The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7. This is due to missing or incorrect nonce validation on the eae_save_config function. This makes it possible for unauthenticated attackers to change configuration settings for the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-4723

Update the WordPress Elementor Addon Elements plugin to the latest available version (at least 1.12.8). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Elementor Addon Elements Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 1.12.8.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-5381

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.12.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-33999

Update the WordPress Elementor Addon Elements plugin to the latest available version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Addon Elements Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.12.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.14

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.14

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Elementor Addon Elements plugin (versions < 1.11.14).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.14

Sensitive Information Disclosure vulnerability discovered in WordPress Elementor Addon Elements plugin (versions < 1.11.14).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.8

The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missing or incorrect nonce validation on the eae_review() and fv_download_box() functions. This makes it possible for unauthenticated attackers to gain administrative access and force unwanted actions on other users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-24259

The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. The “Flip Box” widget accepts a “front_title_html_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request with the “front_title_html_tag” set to JavaScript. Alternatively, it is possible to set “front_title_html_tag” to simply “script” and add the JavaScript to be executed in the “front_title” parameter. This JavaScript will then be executed when the saved page is viewed or previewed. The “back_title_html_tag” parameter appears to be vulnerable to the same exploit. We’ve verified that the Price Table widget is similarly vulnerable via the "heading_tag" and "sub_heading_tag" parameters, and the following widgets are likely also vulnerable to similar exploits: Split Text: "title_size" parameter containing JS Text Separator: "html_tag" containing JS or set to "script" with actual JS to be executed in "title" parameter Timeline: "html_tag" parameter containing JS These vulnerabilities are nearly identical to the vulnerabilities we have recently disclosed in the main Elementor plugin: https://www.wordfence.com/blog/2021/03/cross-site-scripting-vulnerabilities-in-elementor-impact-over-7-million-sites/

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.2

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Elementor Addon Elements plugin (versions <= 1.11.1).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.6.4

Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress Elementor Addon Elements plugin (versions <= 1.6.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.6.4

The Elementor Addon Elements plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 1.6.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.14

The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.8

The plugin does not properly check for CSRF in some of its functions, allowing them to be bypassed when making a requests without the expected nonce parameter (v < 1.1.7) or with a dummy nonce value (v < 1.11.8). As a result, attackers could make users perform unwanted actions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.6.4

Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.