PLUGIN SECURITY

Is Premium Addons For Elementor safe?

Elementor Carousel, Mega Menu, Posts List/Slider, WooCommerce Widgets, Display Conditions, AI Abilities, Premade Templates & more.

What this plugin does

  • Slug: premium-addons-for-elementor
  • Author: Leap13
  • 600000+ active installs
  • 98/100 rating (1677 reviews on wordpress.org)
  • 63995717 all-time downloads
  • On WordPress.org since 2018-01-09

elementorelementor addonselementor aielementor templateselementor widgets

Maintenance status

  • Latest known version: 4.11.96
  • Last updated: 2026-08-25 3:16pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

38 known CVEs on file for Premium Addons For Elementor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12141 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.85 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.9 < 4.11.85 4.11.85 2026-07-10 ✓ fixed in latest
CVE-2026-4790 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.71 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.11.71 4.11.71 2026-05-01 ✓ fixed in latest
CVE-2025-69300 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.64 Missing Authorization Medium 5.4 < 4.11.64 4.11.64 2026-01-17 ✓ fixed in latest
CVE-2025-14163 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.54 Cross-Site Request Forgery (CSRF) Medium 4.3 < 4.11.54 4.11.54 2025-12-22 ✓ fixed in latest
CVE-2025-14155 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.54 Missing Authorization Medium 5.3 < 4.11.54 4.11.54 2025-12-22 ✓ fixed in latest
CVE-2025-68494 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.54 Exposure of Sensitive System Information to an Unauthorized Control Sphere Medium 5.3 < 4.11.54 4.11.54 2025-12-04 ✓ fixed in latest
CVE-2024-11937 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.70 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.10.70 4.10.70 2025-07-03 ✓ fixed in latest
CVE-2024-56225 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.57 Missing Authorization Medium 5.4 < 4.10.57 4.10.57 2024-12-19 ✓ fixed in latest
+ 35 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10266 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.61 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.10.61 4.10.61 2024-10-28 ✓ fixed in latest
CVE-2024-8681 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.53 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.53 4.10.53 2024-09-26 ✓ fixed in latest
CVE-2024-6824 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.39 Missing Authorization Medium 4.3 < 4.10.39 4.10.39 2024-08-07 ✓ fixed in latest
CVE-2024-6495 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.37 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.37 4.10.37 2024-07-11 ✓ fixed in latest
CVE-2024-37922 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.35 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.10.35 4.10.35 2024-07-09 ✓ fixed in latest
CVE-2024-6434 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.36 Uncontrolled Resource Consumption Medium 4.3 < 4.10.36 4.10.36 2024-07-03 ✓ fixed in latest
CVE-2024-6340 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.36 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.36 4.10.36 2024-07-02 ✓ fixed in latest
CVE-2024-5553 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.34 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.34 4.10.34 2024-06-11 ✓ fixed in latest
CVE-2024-4376 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.32 4.10.32 2024-05-30 ✓ fixed in latest
CVE-2024-4205 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.32 Missing Authorization Medium 4.3 < 4.10.32 4.10.32 2024-05-30 ✓ fixed in latest
CVE-2024-4379 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.32 4.10.32 2024-05-30 ✓ fixed in latest
CVE-2024-4378 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.32 4.10.32 2024-05-22 ✓ fixed in latest
CVE-2024-4203 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.31 4.10.31 2024-04-29 ✓ fixed in latest
CVE-2024-3647 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.10.29 4.10.29 2024-04-24 ✓ fixed in latest
CVE-2024-3885 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.29 4.10.29 2024-04-23 ✓ fixed in latest
CVE-2024-32791 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.26 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.10.26 4.10.26 2024-04-22 ✓ fixed in latest
CVE-2024-0376 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.17 4.10.17 2024-04-09 ✓ fixed in latest
CVE-2024-2664 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.10.25 4.10.25 2024-04-09 ✓ fixed in latest
CVE-2024-2665 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.28 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.10.28 4.10.28 2024-04-09 ✓ fixed in latest
CVE-2024-2666 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.25 4.10.25 2024-04-09 ✓ fixed in latest
CVE-2024-31278 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.23 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 4.10.23 4.10.23 2024-04-05 ✓ fixed in latest
CVE-2024-29106 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.10.17 4.10.17 2024-03-19 ✓ fixed in latest
CVE-2024-2399 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.24 4.10.24 2024-03-14 ✓ fixed in latest
CVE-2024-1680 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.22 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.10.22 4.10.22 2024-02-28 ✓ fixed in latest
CVE-2024-0326 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.10.19 4.10.19 2024-02-14 ✓ fixed in latest
CVE-2024-1242 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.10.19 4.10.19 2024-02-14 ✓ fixed in latest
CVE-2024-24831 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.10.17 4.10.17 2024-02-02 ✓ fixed in latest
Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.5.2 Unknown < 4.5.2 4.5.2 2021-08-30 ✓ fixed in latest
CVE-2021-4445 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.5.2 Missing Authorization Medium 4.3 < 4.5.2 4.5.2 2021-08-30 ✓ fixed in latest
CVE-2021-24257 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.2.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.2.8 4.2.8 2021-04-13 ✓ fixed in latest
Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.2.8 Unknown < 4.2.8 4.2.8 2021-04-13 ✓ fixed in latest
Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.11.9 4.11.9 0000-00-00 ✓ fixed in latest
Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.5.2 Unknown < 4.5.2 4.5.2 ✓ fixed in latest
Premium Addons for Elementor < 4.5.2 - Subscriber+ Arbitrary Blog Option Update Unknown < 4.5.2 4.5.2 ✓ fixed in latest
CVE-2025-4774 Premium Addons for Elementor < 4.11.9 - Contributor+ Stored XSS via Countdown Widget Unknown < 4.11.9 4.11.9 ✓ fixed in latest

How to fix it

Keep Premium Addons For Elementor updated — 4.11.96 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.