WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Themesflat Addons For Elementor safe?

Themesflat Addons For Elementor plugin you install after Elementor!. Themesflat addon focuses on support for the author build Template Kits

What this plugin does

  • Slug: themesflat-addons-for-elementor
  • Author: Themesflat
  • 40000+ active installs
  • 40/100 rating (9 reviews on wordpress.org)
  • 710966 all-time downloads
  • On WordPress.org since 2020-07-21

addonselementorelementor addonthemesflatwidget

Maintenance status

  • Last updated: 2026-03-13 2:38am GMT
  • Tested up to WordPress: 6.9.5
  • Requires PHP: 5.2+

Known vulnerabilities

14 known CVEs on file for Themesflat Addons For Elementor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-39500 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.3.3 Medium 6.5 < 2.3.3 2.3.3 2026-03-23
CVE-2025-31567 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.3.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.3.2 2.3.2 2025-03-31
CVE-2024-12205 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.2.5 2.2.5 2025-01-07
CVE-2024-53796 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2.3 2.2.3 2024-12-02
CVE-2024-49310 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2.2 2.2.2 2024-10-15
CVE-2024-8515 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.2.2 2.2.2 2024-09-24
CVE-2024-8516 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 2.2.2 2.2.2 2024-09-24
CVE-2024-2922 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.1.3 2.1.3 2024-06-05

CVE-2026-39500

The themesflat-addons-for-elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-31567

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-12205

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-53796

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-49310

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-8515

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-8516

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and future scheduled posts.

Source: CVE.org

CVE-2024-2922

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-35666 may be a duplicate of this issue.

Source: Wordfence

+ 6 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4459 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.1.3 2.1.3 2024-06-05
CVE-2024-4212 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.1.3 2.1.3 2024-06-05
CVE-2024-4458 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.1.3 2.1.3 2024-06-05
CVE-2024-35666 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.1.3 2.1.3 2024-06-03
CVE-2023-37390 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.0.1 Deserialization of Untrusted Data High 8.3 < 2.0.1 2.0.1 2023-08-07
CVE-2025-3275 Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.2.6 2.2.6 0000-00-00

CVE-2024-4459

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-4212

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-4458

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-35666

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.1.2.

Source: CVE.org

CVE-2023-37390

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.0 via deserialization of untrusted input through the 'settings' parameter retrieved from the tf_product_filter nopriv AJAX action. This allows unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Source: Wordfence

CVE-2025-3275

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.