PLUGIN SECURITY
Is The Plus Addons For Elementor Page Builder safe?
Best Addons for Elementor with 120+ Elementor FREE & Pro Widgets & 1000+ Elementor Templates with Mega Menu, Post Grid, Header Footer, WooCommerce
What this plugin does
- Slug:
the-plus-addons-for-elementor-page-builder - Author: POSIMYTH
- 100000+ active installs
- 92/100 rating (387 reviews on wordpress.org)
- 6284195 all-time downloads
- On WordPress.org since 2018-12-29
elementorelementor addonselementor templateselementor widgetswidgets for elementor
Maintenance status
- Latest known version: 6.4.17
- Last updated: 2026-08-21 6:01am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
Known vulnerabilities
39 known CVEs on file for The Plus Addons For Elementor Page Builder.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-9243 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.4.16 | 6.4.16 | 2026-05-28 | ✓ fixed in latest |
| CVE-2026-15285 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.4.12 | 6.4.12 | 2026-05-21 | ✓ fixed in latest |
| — | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.12 | — | Unknown | < 6.4.12 | 6.4.12 | 2026-05-21 | ✓ fixed in latest |
| CVE-2026-5243 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.4.12 | 6.4.12 | 2026-05-13 | ✓ fixed in latest |
| CVE-2025-55712 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.14 | Missing Authorization | Medium 6.5 | < 6.3.14 | 6.3.14 | 2025-08-14 | ✓ fixed in latest |
| CVE-2025-49076 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.2.8 | 6.2.8 | 2025-05-30 | ✓ fixed in latest |
| CVE-2024-11829 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.2.0 | 6.2.0 | 2025-01-31 | ✓ fixed in latest |
| CVE-2024-53823 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.0.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.0.1 | 6.0.1 | 2024-12-02 | ✓ fixed in latest |
+ 41 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-10365 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.0.4 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 4.3 | < 6.0.4 | 6.0.4 | 2024-11-19 | ✓ fixed in latest |
| CVE-2024-8913 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.12 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 4.3 | < 5.6.12 | 5.6.12 | 2024-10-10 | ✓ fixed in latest |
| CVE-2024-43977 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.6.3 | 5.6.3 | 2024-08-28 | ✓ fixed in latest |
| CVE-2024-43932 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3 | Missing Authorization | Medium 6.5 | < 5.6.3 | 5.6.3 | 2024-08-26 | ✓ fixed in latest |
| CVE-2024-5583 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.3 | 5.6.3 | 2024-08-21 | ✓ fixed in latest |
| CVE-2024-5763 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.3 | 5.6.3 | 2024-08-19 | ✓ fixed in latest |
| CVE-2024-6575 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.3 | 5.6.3 | 2024-08-19 | ✓ fixed in latest |
| CVE-2024-4482 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.2 | 5.6.2 | 2024-07-02 | ✓ fixed in latest |
| CVE-2024-4983 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.1 | 5.6.1 | 2024-06-26 | ✓ fixed in latest |
| CVE-2024-35709 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.5.5 | 5.5.5 | 2024-06-06 | ✓ fixed in latest |
| CVE-2024-4485 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.3 | 5.5.3 | 2024-05-23 | ✓ fixed in latest |
| CVE-2024-3718 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.5 | 5.5.5 | 2024-05-23 | ✓ fixed in latest |
| CVE-2024-4484 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.3 | 5.5.3 | 2024-05-23 | ✓ fixed in latest |
| CVE-2024-2784 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.5 | 5.5.5 | 2024-05-23 | ✓ fixed in latest |
| CVE-2024-2785 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.0 | 5.5.0 | 2024-05-06 | ✓ fixed in latest |
| CVE-2024-0445 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.0 | 5.5.0 | 2024-05-06 | ✓ fixed in latest |
| CVE-2024-34373 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.5.0 | 5.5.0 | 2024-05-03 | ✓ fixed in latest |
| CVE-2024-3197 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.0 | 5.5.0 | 2024-04-25 | ✓ fixed in latest |
| CVE-2024-3199 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.0 | 5.5.0 | 2024-04-25 | ✓ fixed in latest |
| CVE-2024-2210, CVE-2024-2203 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.2 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.4 | < 5.4.2 | 5.4.2 | 2024-03-26 | ✓ fixed in latest |
| CVE-2024-2203 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.2 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.8 | < 5.4.2 | 5.4.2 | 2024-03-26 | ✓ fixed in latest |
| CVE-2024-1419 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.4.1 | 5.4.1 | 2024-03-06 | ✓ fixed in latest |
| CVE-2024-23511 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.3.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.3.4 | 5.3.4 | 2024-01-30 | ✓ fixed in latest |
| CVE-2021-4331 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.7 | Missing Authorization | High 8.8 | < 2.0.7 | 2.0.7 | 2021-04-14 | ✓ fixed in latest |
| CVE-2021-4332 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.7 | External Control of File Name or Path | Medium 6.5 | < 2.0.7 | 2.0.7 | 2021-04-14 | ✓ fixed in latest |
| CVE-2021-24266 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.0.6 | 2.0.6 | 2021-04-13 | ✓ fixed in latest |
| — | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.6 | — | Unknown | < 2.0.6 | 2.0.6 | 2021-04-13 | ✓ fixed in latest |
| — | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.2.3 | 6.2.3 | 0000-00-00 | ✓ fixed in latest |
| — | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 6.3.11 | 6.3.11 | 0000-00-00 | ✓ fixed in latest |
| — | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.16 | — | Medium 6.8 | < 6.3.16 | 6.3.16 | 0000-00-00 | ✓ fixed in latest |
| — | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.10 | — | Unknown | < 6.4.10 | 6.4.10 | 0000-00-00 | ✓ fixed in latest |
| — | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.8 | — | Unknown | < 6.4.8 | 6.4.8 | 0000-00-00 | ✓ fixed in latest |
| — | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.8 | — | Unknown | < 6.4.8 | 6.4.8 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-1287 | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce < 6.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | — | Unknown | < 6.2.3 | 6.2.3 | — | ✓ fixed in latest |
| CVE-2025-7646 | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce < 6.3.11 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 6.3.11 | 6.3.11 | — | ✓ fixed in latest |
| CVE-2025-9698 | The Plus Addons for Elementor < 6.3.16 - Author+ Stored XSS | — | Unknown | < 6.3.16 | 6.3.16 | — | ✓ fixed in latest |
| CVE-2026-2386 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce < 6.4.8 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' | — | Unknown | < 6.4.8 | 6.4.8 | — | ✓ fixed in latest |
| CVE-2026-2385 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce < 6.4.8 - Unauthenticated Email Relay | — | Unknown | < 6.4.8 | 6.4.8 | — | ✓ fixed in latest |
| CVE-2026-3311 | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce < 6.4.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar | — | Unknown | < 6.4.10 | 6.4.10 | — | ✓ fixed in latest |
| CVE-2026-15285 | The Plus Addons for Elementor < 6.4.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes | — | Unknown | < 6.4.12 | 6.4.12 | — | ✓ fixed in latest |
| — | The Plus Addons for Elementor < 6.4.12 - Contributor+ Stored Cross-Site Scripting | — | Unknown | < 6.4.12 | 6.4.12 | — | ✓ fixed in latest |
How to fix it
Keep The Plus Addons For Elementor Page Builder updated — 6.4.17 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Elementor Website Builder – more than just a page builder — 10000000+ active installs — 90/100 (7296)
- Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder — 2000000+ active installs — 98/100 (2525) — max PHP 8.4
- Essential Addons for Elementor – Popular Elementor Templates & Widgets — 1000000+ active installs — 98/100 (4110) — max PHP 8.4
- Starter Templates – AI-Powered Templates for Elementor & Gutenberg — 1000000+ active installs — 98/100 (4745) — max PHP 8.4
- ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor — 1000000+ active installs — 98/100 (2036) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.