PLUGIN SECURITY
Is Piotnet Addons For Elementor safe?
Piotnet Addons For Elementor (PAFE) adds many new features for Elementor
What this plugin does
- Slug:
piotnet-addons-for-elementor - Author: piotnetdotcom
- 30000+ active installs
- 64/100 rating (57 reviews on wordpress.org)
- 723316 all-time downloads
- On WordPress.org since 2018-11-12
elementor addonsgradient buttongradient textimage carousel multiple custom urlspafe
Maintenance status
- Latest known version: 2.4.37
- Last updated: 2026-06-17 9:49am GMT
- Tested up to WordPress: 6.8.8
- Requires PHP: 5.4+
Known vulnerabilities
11 known CVEs on file for Piotnet Addons For Elementor.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Piotnet Addons For Elementor [piotnet-addons-for-elementor] <= 2.4.36 (unfixed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.4.36 | 2.4.36 | 2025-04-17 | ✓ fixed in latest |
| — | Piotnet Addons For Elementor [piotnet-addons-for-elementor] <= 2.4.36 (unfixed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.4.36 | 2.4.36 | 2025-04-04 | ✓ fixed in latest |
| CVE-2024-10775 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.33 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 2.4.33 | 2.4.33 | 2025-01-14 | ✓ fixed in latest |
| CVE-2025-22333 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.4.32 | 2.4.32 | 2025-01-03 | ✓ fixed in latest |
| CVE-2024-5502 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.31 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.4.31 | 2.4.31 | 2024-08-22 | ✓ fixed in latest |
| CVE-2024-5614 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.30 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 2.4.30 | 2.4.30 | 2024-07-26 | ✓ fixed in latest |
| CVE-2024-4262 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.29 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.4.29 | 2.4.29 | 2024-05-21 | ✓ fixed in latest |
| CVE-2024-4432 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.28 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.4.28 | 2.4.28 | 2024-05-17 | ✓ fixed in latest |
+ 5 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-33630 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.27 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.4.27 | 2.4.27 | 2024-04-25 | ✓ fixed in latest |
| CVE-2024-29934 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.26 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.4.26 | 2.4.26 | 2024-03-25 | ✓ fixed in latest |
| CVE-2024-9673 | Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32 | — | Unknown | < 2.4.32 | 2.4.32 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-32197 | Piotnet Addons For Elementor <= 2.4.36 - Contributor+ Stored XSS | — | Unknown | not specified | no fix on file | — | — |
| CVE-2024-13650 | Piotnet Addons For Elementor <= 2.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | not specified | no fix on file | — | — |
How to fix it
Keep Piotnet Addons For Elementor updated — 2.4.37 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
2 of the vulnerabilities above have no fixed version on file — there's no update that resolves them. Consider deactivating this plugin or switching to one of the alternatives below.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder — 2000000+ active installs — 98/100 (2525) — max PHP 8.4
- Essential Addons for Elementor – Popular Elementor Templates & Widgets — 1000000+ active installs — 98/100 (4110) — max PHP 8.4
- ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor — 1000000+ active installs — 98/100 (2036) — max PHP 8.4
- Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools — 600000+ active installs — 98/100 (1677) — max PHP 8.4
- Royal Addons for Elementor – Addons and Templates Kit for Elementor — 600000+ active installs — 96/100 (611)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.