PLUGIN SECURITY

Is Envo Extra safe?

Extra addon for EnvoThemes Themes

What this plugin does

  • Slug: envo-extra
  • Author: EnvoThemes
  • 20000+ active installs
  • 717059 all-time downloads
  • On WordPress.org since 2022-10-18

demoelementorenvothemeswoocommerce

Maintenance status

  • Latest known version: 1.9.21
  • Last updated: 2026-08-20 8:25am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 5.6+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

7 known CVEs on file for Envo Extra. Reported between 2023 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-32386 Envo Extra [envo-extra] < 1.9.14 Missing Authorization Medium 4.3 < 1.9.14 1.9.14 2026-02-18 ✓ fixed in latest
CVE-2025-66066 Envo Extra [envo-extra] < 1.9.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 1.9.12 1.9.12 2025-11-21 ✓ fixed in latest
CVE-2025-47471 Envo Extra [envo-extra] < 1.9.10 Missing Authorization Medium 4.3 < 1.9.10 1.9.10 2025-05-07 ✓ fixed in latest
CVE-2024-10770 Envo Extra [envo-extra] < 1.9.4 Authorization Bypass Through User-Controlled Key Medium 4.3 < 1.9.4 1.9.4 2024-11-08 ✓ fixed in latest
CVE-2024-5645 Envo Extra [envo-extra] < 1.8.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.8.25 1.8.25 2024-06-06 ✓ fixed in latest
CVE-2024-4385 Envo Extra [envo-extra] < 1.8.17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.8.17 1.8.17 2024-05-15 ✓ fixed in latest
CVE-2024-32456 Envo Extra [envo-extra] < 1.8.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.8.12 1.8.12 2024-04-15 ✓ fixed in latest
Envo Extra [envo-extra] < 1.8.4 Unknown < 1.8.4 1.8.4 2023-10-18 ✓ fixed in latest
+ 3 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Envo Extra [envo-extra] < 1.8.4 Unknown < 1.8.4 1.8.4 2023-10-17 ✓ fixed in latest
Envo Extra [envo-extra] < 1.8.4 Unknown < 1.8.4 1.8.4 ✓ fixed in latest
Envo Extra < 1.8.4 - Cross-Site Request Forgery Unknown < 1.8.4 1.8.4 ✓ fixed in latest

How to fix it

Keep Envo Extra updated — 1.9.21 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.