Elementinvader develops plugin extensions for the Elementor page builder platform, occupying a specialized niche within the WordPress ecosystem. The vendor's vulnerability profile centers on its addon suite and recurs through application-layer weaknesses including cross-site scripting, authorization bypass, sensitive information disclosure, and path traversal, reflecting common attack surfaces in user-facing web-plugin architecture. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elementinvader over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57376HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for- | Jul 13, 2026 | 7.1 | 32 | NO | NO |
CVE-2026-25007HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for- | Mar 25, 2026 | 8.5 | 26 | NO | NO |
CVE-2025-22786HIGH Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows PHP Local File Inclusion.This issue affe | Jan 15, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-24618HIGH Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Contr | Jan 24, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-58205MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for- | Aug 27, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-2308MEDIUM The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up to, and including, | Mar 16, 2024 | 5.4 | 20 | NO | NO |
CVE-2026-25028MEDIUM Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Contr | Feb 3, 2026 | 5.4 | 19 | NO | NO |
CVE-2025-48288MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for- | May 19, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-24729MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for- | Jan 24, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-47630MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for- | Oct 5, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elementinvader.
Media articles that mention a CVE ID that affects a product developed by Elementinvader — matched by CVE ID, not by vendor name.