PLUGIN SECURITY
Is Envo Extra safe?
Extra addon for EnvoThemes Themes
What this plugin does
- Slug:
envo-extra - Author: EnvoThemes
- 20000+ active installs
- 717059 all-time downloads
- On WordPress.org since 2022-10-18
demoelementorenvothemeswoocommerce
Maintenance status
- Latest known version: 1.9.21
- Last updated: 2026-08-20 8:25am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
7 known CVEs on file for Envo Extra. Reported between 2023 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-32386 | Envo Extra [envo-extra] < 1.9.14 | Missing Authorization | Medium 4.3 | < 1.9.14 | 1.9.14 | 2026-02-18 | ✓ fixed in latest |
| CVE-2025-66066 | Envo Extra [envo-extra] < 1.9.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 1.9.12 | 1.9.12 | 2025-11-21 | ✓ fixed in latest |
| CVE-2025-47471 | Envo Extra [envo-extra] < 1.9.10 | Missing Authorization | Medium 4.3 | < 1.9.10 | 1.9.10 | 2025-05-07 | ✓ fixed in latest |
| CVE-2024-10770 | Envo Extra [envo-extra] < 1.9.4 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 1.9.4 | 1.9.4 | 2024-11-08 | ✓ fixed in latest |
| CVE-2024-5645 | Envo Extra [envo-extra] < 1.8.25 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.8.25 | 1.8.25 | 2024-06-06 | ✓ fixed in latest |
| CVE-2024-4385 | Envo Extra [envo-extra] < 1.8.17 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.8.17 | 1.8.17 | 2024-05-15 | ✓ fixed in latest |
| CVE-2024-32456 | Envo Extra [envo-extra] < 1.8.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.8.12 | 1.8.12 | 2024-04-15 | ✓ fixed in latest |
| — | Envo Extra [envo-extra] < 1.8.4 | — | Unknown | < 1.8.4 | 1.8.4 | 2023-10-18 | ✓ fixed in latest |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Envo Extra [envo-extra] < 1.8.4 | — | Unknown | < 1.8.4 | 1.8.4 | 2023-10-17 | ✓ fixed in latest |
| — | Envo Extra [envo-extra] < 1.8.4 | — | Unknown | < 1.8.4 | 1.8.4 | — | ✓ fixed in latest |
| — | Envo Extra < 1.8.4 - Cross-Site Request Forgery | — | Unknown | < 1.8.4 | 1.8.4 | — | ✓ fixed in latest |
How to fix it
Keep Envo Extra updated — 1.9.21 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Elementor Website Builder – more than just a page builder — 10000000+ active installs — 90/100 (7296)
- Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder — 2000000+ active installs — 98/100 (2525) — max PHP 8.4
- Essential Addons for Elementor – Popular Elementor Templates & Widgets — 1000000+ active installs — 98/100 (4110) — max PHP 8.4
- Starter Templates – AI-Powered Templates for Elementor & Gutenberg — 1000000+ active installs — 98/100 (4745) — max PHP 8.4
- Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools — 600000+ active installs — 98/100 (1677) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.