PLUGIN SECURITY

Is Premium Addons Pro safe?

Elementor Carousel, Mega Menu, Posts List/Slider, WooCommerce Widgets, Display Conditions, AI Abilities, Premade Templates & more.

What this plugin does

  • Slug: premium-addons-pro
  • Author: Leap13
  • 600000+ active installs
  • 98/100 rating (1677 reviews on wordpress.org)
  • 64370577 all-time downloads
  • On WordPress.org since 2018-01-09

elementorelementor addonselementor aielementor templateselementor widgets

Maintenance status

  • Latest known version: 4.11.96
  • Last updated: 2026-09-03 2:36pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+

Known vulnerabilities

10 known CVEs on file for Premium Addons Pro. Reported between 2023 and 2024.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2239 Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.13 2.9.13 2024-03-07 ✓ fixed in latest
CVE-2024-2238 Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.13 2.9.13 2024-03-07 ✓ fixed in latest
CVE-2024-1997 Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.13 2.9.13 2024-03-07 ✓ fixed in latest
CVE-2024-2000 Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.13 2.9.13 2024-03-07 ✓ fixed in latest
CVE-2024-2237 Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.13 2.9.13 2024-03-07 ✓ fixed in latest
CVE-2024-1996 Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.13 2.9.13 2024-03-06 ✓ fixed in latest
CVE-2023-37869 Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.1 Missing Authorization Medium 6.5 < 2.9.1 2.9.1 2023-07-10 ✓ fixed in latest
CVE-2023-37868 Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 2.9.1 2.9.1 2023-07-10 ✓ fixed in latest
+ 2 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-34012 Premium Addons Pro for Elementor [premium-addons-pro] < 2.8.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.8.25 2.8.25 2023-06-02 ✓ fixed in latest
CVE-2024-2399 Premium Addons for Elementor (Free < 4.10.24, Pro < 2.9.14) - Contributor+ Stored XSS Unknown < 2.9.14 2.9.14 ✓ fixed in latest

How to fix it

Keep Premium Addons Pro updated — 4.11.96 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.