PLUGIN SECURITY
Is Essential Addons for Elementor safe?
Elementor addon offering 120+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
What this plugin does
- Slug:
essential-addons-for-elementor-lite - Author: WPDeveloper
- 1000000+ active installs
- 98/100 rating (4112 reviews on wordpress.org)
- 132625122 all-time downloads
- On WordPress.org since 2017-07-20
elementorelementor addonselementor templateselementor widgetselementor woocommerce
Maintenance status
- Latest known version: 6.7.2
- Last updated: 2026-08-27 7:26pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.0+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
68 known CVEs on file for Essential Addons for Elementor.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-81777 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.8.1 | Authentication Bypass by Spoofing | Medium 5.3 | < 6.8.1 | 6.8.1 | 2026-08-28 | ⚠ update needed |
| CVE-2026-13345 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.10 | Authorization Bypass Through User-Controlled Key | Unknown | < 6.6.10 | 6.6.10 | 2026-07-30 | ✓ fixed in latest |
| CVE-2026-13344 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 6.6.10 | 6.6.10 | 2026-07-30 | ✓ fixed in latest |
| CVE-2026-18039 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.7.2 | Improper Privilege Management | Unknown | < 6.7.2 | 6.7.2 | 2026-07-30 | ✓ fixed in latest |
| CVE-2026-15145 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.7.0 | 6.7.0 | 2026-07-20 | ✓ fixed in latest |
| CVE-2026-15156 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.7.0 | 6.7.0 | 2026-07-20 | ✓ fixed in latest |
| CVE-2026-15155 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.11 | Weak Password Recovery Mechanism for Forgotten Password | High 8.8 | < 6.6.11 | 6.6.11 | 2026-07-10 | ✓ fixed in latest |
| CVE-2026-6459 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.6.3 | 6.6.3 | 2026-07-07 | ✓ fixed in latest |
+ 69 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-7665 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.5 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 6.6.5 | 6.6.5 | 2026-06-05 | ✓ fixed in latest |
| CVE-2026-5193 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.0 | Improper Privilege Management | Medium 6.5 | < 6.6.0 | 6.6.0 | 2026-05-13 | ✓ fixed in latest |
| CVE-2026-25440 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.0 | Missing Authorization | Medium 5.3 | < 6.6.0 | 6.6.0 | 2026-04-22 | ✓ fixed in latest |
| CVE-2025-69092 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.5.4 | 6.5.4 | 2025-12-30 | ✓ fixed in latest |
| CVE-2025-13977 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.5.4 | 6.5.4 | 2025-12-16 | ✓ fixed in latest |
| CVE-2026-23543 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.6 | Missing Authorization | Medium 5.3 | < 6.5.6 | 6.5.6 | 2025-11-18 | ✓ fixed in latest |
| CVE-2025-64352 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.3.0 | Missing Authorization | Low 2.7 | < 6.3.0 | 6.3.0 | 2025-09-17 | ✓ fixed in latest |
| CVE-2024-5647 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.0.5 | 6.0.5 | 2025-07-02 | ✓ fixed in latest |
| CVE-2025-39589 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.10 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | Medium 4.3 | < 6.1.10 | 6.1.10 | 2025-04-16 | ✓ fixed in latest |
| CVE-2025-39590 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.1.10 | 6.1.10 | 2025-04-16 | ✓ fixed in latest |
| CVE-2025-24752 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.15 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 6.0.15 | 6.0.15 | 2025-02-04 | ✓ fixed in latest |
| CVE-2024-56063 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.0.8 | 6.0.8 | 2024-12-18 | ✓ fixed in latest |
| CVE-2024-8979 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.10 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.7 | < 6.0.10 | 6.0.10 | 2024-11-14 | ✓ fixed in latest |
| CVE-2024-8961 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.0.8 | 6.0.8 | 2024-11-14 | ✓ fixed in latest |
| CVE-2024-8978 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.10 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.7 | < 6.0.10 | 6.0.10 | 2024-11-14 | ✓ fixed in latest |
| CVE-2024-8742 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.0.4 | 6.0.4 | 2024-09-12 | ✓ fixed in latest |
| CVE-2024-8440 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.0.4 | 6.0.4 | 2024-09-10 | ✓ fixed in latest |
| CVE-2024-7092 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.0.0 | 6.0.0 | 2024-08-12 | ✓ fixed in latest |
| CVE-2024-39649 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.27 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.9.27 | 5.9.27 | 2024-08-01 | ✓ fixed in latest |
| CVE-2024-5189 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.24 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.24 | 5.9.24 | 2024-06-10 | ✓ fixed in latest |
| CVE-2024-5188 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.23 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.23 | 5.9.23 | 2024-06-05 | ✓ fixed in latest |
| CVE-2024-5073 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.22 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.22 | 5.9.22 | 2024-05-29 | ✓ fixed in latest |
| CVE-2024-34764 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 5.9.16 | 5.9.16 | 2024-05-17 | ✓ fixed in latest |
| CVE-2024-4624 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.21 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.21 | 5.9.21 | 2024-05-13 | ✓ fixed in latest |
| CVE-2024-4448 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.9.20 | 5.9.20 | 2024-05-09 | ✓ fixed in latest |
| CVE-2024-4275 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.20 | 5.9.20 | 2024-05-09 | ✓ fixed in latest |
| CVE-2024-4449 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.20 | 5.9.20 | 2024-05-09 | ✓ fixed in latest |
| CVE-2024-4156 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.18 | 5.9.18 | 2024-04-30 | ✓ fixed in latest |
| CVE-2024-3733 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 5.9.16 | 5.9.16 | 2024-04-24 | ✓ fixed in latest |
| CVE-2024-3728 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.9.16 | 5.9.16 | 2024-04-24 | ✓ fixed in latest |
| CVE-2024-4003 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16 | Improper Input Validation | Medium 5.4 | < 5.9.16 | 5.9.16 | 2024-04-24 | ✓ fixed in latest |
| CVE-2024-3333 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.15 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.9.15 | 5.9.15 | 2024-04-16 | ✓ fixed in latest |
| CVE-2024-3018 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.14 | Deserialization of Untrusted Data | High 8.8 | < 5.9.14 | 5.9.14 | 2024-03-29 | ✓ fixed in latest |
| CVE-2024-2974 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.14 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 5.9.14 | 5.9.14 | 2024-03-29 | ✓ fixed in latest |
| CVE-2024-2623 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.9.12 | 5.9.12 | 2024-03-25 | ✓ fixed in latest |
| CVE-2024-2650 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.12 | Improper Input Validation | Medium 6.4 | < 5.9.12 | 5.9.12 | 2024-03-25 | ✓ fixed in latest |
| CVE-2024-1537 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.9.10 | 5.9.10 | 2024-03-11 | ✓ fixed in latest |
| CVE-2024-1536 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.4 | < 5.9.10 | 5.9.10 | 2024-03-11 | ✓ fixed in latest |
| CVE-2024-1171 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.9 | 5.9.9 | 2024-02-12 | ✓ fixed in latest |
| CVE-2024-1236 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.9.9 | 5.9.9 | 2024-02-12 | ✓ fixed in latest |
| CVE-2024-1276 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.9.9 | 5.9.9 | 2024-02-12 | ✓ fixed in latest |
| CVE-2024-1172 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.9 | 5.9.9 | 2024-02-12 | ✓ fixed in latest |
| CVE-2024-0954 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.8 | 5.9.8 | 2024-02-01 | ✓ fixed in latest |
| CVE-2024-0586 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.5 | 5.9.5 | 2024-01-17 | ✓ fixed in latest |
| CVE-2024-0585 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.5 | 5.9.5 | 2024-01-17 | ✓ fixed in latest |
| CVE-2023-7044 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.9.3 | 5.9.3 | 2024-01-03 | ✓ fixed in latest |
| CVE-2023-41955 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.8.9 | Improper Privilege Management | High 8.8 | < 5.8.9 | 5.8.9 | 2023-09-14 | ✓ fixed in latest |
| CVE-2023-3779 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.8.2 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 5.8.2 | 5.8.2 | 2023-07-19 | ✓ fixed in latest |
| CVE-2023-32243 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.7.2 | Improper Authentication | Critical 9.8 | < 5.7.2 | 5.7.2 | 2023-05-11 | ✓ fixed in latest |
| CVE-2022-0683 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.0.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.0.9 | 5.0.9 | 2022-02-18 | ✓ fixed in latest |
| CVE-2022-0320 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.0.9 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Critical 9.8 | < 5.0.9 | 5.0.9 | 2022-01-21 | ✓ fixed in latest |
| CVE-2021-4446 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.6.5 | Missing Authorization | Medium 4.3 | < 4.6.5 | 4.6.5 | 2021-05-05 | ✓ fixed in latest |
| CVE-2021-4447 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.6.5 | Missing Authorization | High 8.8 | < 4.6.5 | 4.6.5 | 2021-05-05 | ✓ fixed in latest |
| CVE-2021-24255 | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.5.4 | 4.5.4 | 2021-04-13 | ✓ fixed in latest |
| — | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.5.4 | — | Unknown | < 4.5.4 | 4.5.4 | 2021-04-13 | ✓ fixed in latest |
| — | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.1.13 | 6.1.13 | 0000-00-00 | ✓ fixed in latest |
| — | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.1.13 | 6.1.13 | 0000-00-00 | ✓ fixed in latest |
| — | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.1.20 | 6.1.20 | 0000-00-00 | ✓ fixed in latest |
| — | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.2.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.2.3 | 6.2.3 | 0000-00-00 | ✓ fixed in latest |
| — | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.10 | — | Unknown | < 6.5.10 | 6.5.10 | 0000-00-00 | ✓ fixed in latest |
| — | Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.6 | — | Unknown | < 6.5.6 | 6.5.6 | 0000-00-00 | ✓ fixed in latest |
| CVE-2023-41955 | Essential Addons for Elementor < 5.8.9 - Authenticated (Contributor+) Privilege Escalation | — | Unknown | < 5.8.9 | 5.8.9 | — | ✓ fixed in latest |
| CVE-2024-9994 | Essential Addons for Elementor < 6.1.13 - Contributor+ Stored XSS via Pricing Table Widget | — | Unknown | < 6.1.13 | 6.1.13 | — | ✓ fixed in latest |
| CVE-2024-9993 | Essential Addons for Elementor < 6.1.13 - Contributor+ Stored XSS via Event Calendar Widget | — | Unknown | < 6.1.13 | 6.1.13 | — | ✓ fixed in latest |
| CVE-2024-5647 | Magnific Popups JavaScript Library < 1.2.0 - Contributor+ Stored XSS | — | Unknown | < 6.0.5 | 6.0.5 | — | ✓ fixed in latest |
| CVE-2025-6244 | Essential Addons for Elementor – Popular Elementor Templates and Widgets < 6.1.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets | — | Unknown | < 6.1.20 | 6.1.20 | — | ✓ fixed in latest |
| CVE-2025-8451 | Essential Addons for Elementor < 6.2.3 - Contributor+ DOM-Based Stored XSS | — | Unknown | < 6.2.3 | 6.2.3 | — | ✓ fixed in latest |
| CVE-2026-1004 | Essential Addons for Elementor < 6.5.6 - Unauthenticated Sensitive Information Exposure | — | Unknown | < 6.5.6 | 6.5.6 | — | ✓ fixed in latest |
| CVE-2026-1512 | Essential Addons for Elementor < 6.5.10 - Contributor+ Stored XSS | — | Unknown | < 6.5.10 | 6.5.10 | — | ✓ fixed in latest |
How to fix it
Keep Essential Addons for Elementor updated — 6.7.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Elementor Website Builder – more than just a page builder — 10000000+ active installs — 90/100 (7297)
- Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder — 2000000+ active installs — 98/100 (2525) — max PHP 8.4
- Starter Templates – AI-Powered Templates for Elementor & Gutenberg — 1000000+ active installs — 98/100 (4745) — max PHP 8.4
- ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor — 1000000+ active installs — 98/100 (2036) — max PHP 8.4
- Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools — 600000+ active installs — 98/100 (1677) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.