Themesflat Addons For Elementor plugin you install after Elementor!. Themesflat addon focuses on support for the author build Template Kits
What this plugin does
- Slug:
themesflat-addons-for-elementor
- Author: Themesflat
- 40000+ active installs
- 40/100 rating (9 reviews on wordpress.org)
- 710966 all-time downloads
- On WordPress.org since 2020-07-21
addonselementorelementor addonthemesflatwidget
Maintenance status
- Last updated: 2026-03-13 2:38am GMT
- Tested up to WordPress: 6.9.5
- Requires PHP: 5.2+
Known vulnerabilities
14 known CVEs on file for Themesflat Addons For Elementor.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-39500
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.3.3 |
— |
Medium
6.5
|
< 2.3.3
|
2.3.3 |
2026-03-23 |
—
|
|
CVE-2025-31567
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.3.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.5
|
< 2.3.2
|
2.3.2 |
2025-03-31 |
—
|
|
CVE-2024-12205
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.5 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 2.2.5
|
2.2.5 |
2025-01-07 |
—
|
|
CVE-2024-53796
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.5
|
< 2.2.3
|
2.2.3 |
2024-12-02 |
—
|
|
CVE-2024-49310
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.5
|
< 2.2.2
|
2.2.2 |
2024-10-15 |
—
|
|
CVE-2024-8515
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.2.2
|
2.2.2 |
2024-09-24 |
—
|
|
CVE-2024-8516
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
4.3
|
< 2.2.2
|
2.2.2 |
2024-09-24 |
—
|
|
CVE-2024-2922
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.1.3
|
2.1.3 |
2024-06-05 |
—
|
CVE-2026-39500
The themesflat-addons-for-elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
CVE-2025-31567
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
CVE-2024-12205
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-53796
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
CVE-2024-49310
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
CVE-2024-8515
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-8516
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and future scheduled posts.
Source:
CVE.org
CVE-2024-2922
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-35666 may be a duplicate of this issue.
Source:
Wordfence
+ 6 more known vulnerabilities
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-4459
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.1.3
|
2.1.3 |
2024-06-05 |
—
|
|
CVE-2024-4212
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.1.3
|
2.1.3 |
2024-06-05 |
—
|
|
CVE-2024-4458
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.1.3
|
2.1.3 |
2024-06-05 |
—
|
|
CVE-2024-35666
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.1.3
|
2.1.3 |
2024-06-03 |
—
|
|
CVE-2023-37390
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.0.1 |
Deserialization of Untrusted Data |
High
8.3
|
< 2.0.1
|
2.0.1 |
2023-08-07 |
—
|
|
CVE-2025-3275
|
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.6 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 2.2.6
|
2.2.6 |
0000-00-00 |
—
|
CVE-2024-4459
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-4212
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-4458
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-35666
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.1.2.
Source:
CVE.org
CVE-2023-37390
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.0 via deserialization of untrusted input through the 'settings' parameter retrieved from the tf_product_filter nopriv AJAX action. This allows unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Source:
Wordfence
CVE-2025-3275
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives