PLUGIN SECURITY

Is Piotnet Addons For Elementor safe?

Piotnet Addons For Elementor (PAFE) adds many new features for Elementor

What this plugin does

  • Slug: piotnet-addons-for-elementor
  • Author: piotnetdotcom
  • 30000+ active installs
  • 64/100 rating (57 reviews on wordpress.org)
  • 723316 all-time downloads
  • On WordPress.org since 2018-11-12

elementor addonsgradient buttongradient textimage carousel multiple custom urlspafe

Maintenance status

  • Latest known version: 2.4.37
  • Last updated: 2026-06-17 9:49am GMT
  • Tested up to WordPress: 6.8.8
  • Requires PHP: 5.4+

Known vulnerabilities

11 known CVEs on file for Piotnet Addons For Elementor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
Piotnet Addons For Elementor [piotnet-addons-for-elementor] <= 2.4.36 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.4.36 2.4.36 2025-04-17 ✓ fixed in latest
Piotnet Addons For Elementor [piotnet-addons-for-elementor] <= 2.4.36 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.4.36 2.4.36 2025-04-04 ✓ fixed in latest
CVE-2024-10775 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.33 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.4.33 2.4.33 2025-01-14 ✓ fixed in latest
CVE-2025-22333 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.4.32 2.4.32 2025-01-03 ✓ fixed in latest
CVE-2024-5502 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.4.31 2.4.31 2024-08-22 ✓ fixed in latest
CVE-2024-5614 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.30 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.4.30 2.4.30 2024-07-26 ✓ fixed in latest
CVE-2024-4262 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.4.29 2.4.29 2024-05-21 ✓ fixed in latest
CVE-2024-4432 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.28 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.4.28 2.4.28 2024-05-17 ✓ fixed in latest
+ 5 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-33630 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.4.27 2.4.27 2024-04-25 ✓ fixed in latest
CVE-2024-29934 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.26 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.4.26 2.4.26 2024-03-25 ✓ fixed in latest
CVE-2024-9673 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32 Unknown < 2.4.32 2.4.32 0000-00-00 ✓ fixed in latest
CVE-2025-32197 Piotnet Addons For Elementor <= 2.4.36 - Contributor+ Stored XSS Unknown not specified no fix on file
CVE-2024-13650 Piotnet Addons For Elementor <= 2.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting Unknown not specified no fix on file

How to fix it

Keep Piotnet Addons For Elementor updated — 2.4.37 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

2 of the vulnerabilities above have no fixed version on file — there's no update that resolves them. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.