Envothemes develops WordPress plugins focused on Elementor templates and WooCommerce integration, serving website builders and e-commerce platforms with a narrow but strategically positioned product line. Its vulnerability profile centers on web application input-handling and authorization weaknesses, including cross-site scripting, cross-site request forgery, and access-control bypass patterns that are characteristic of plugins operating at the intersection of user-generated content and commerce functionality. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Envothemes over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32386MEDIUM Missing Authorization vulnerability in EnvoThemes Envo Extra envo-extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envo Extra: from | Mar 13, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-66066MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra envo-extra allows Stored XSS.This issue affects Envo Ext | Nov 21, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-43292MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows | Aug 18, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-50447MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce envo-elementor | Oct 28, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-4385MEDIUM The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient input sanitiza | May 16, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-10770MEDIUM The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 via the 'elementor-template' shortcode due to insufficient res | Nov 9, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-5645MEDIUM The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter within the Button widget in all versions up to, and including, 1. | Jun 7, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-35167MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored | May 14, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-32456MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra allows Stored XSS.This issue affects Envo Extra: from n/ | Apr 17, 2024 | 5.4 | 16 | NO | NO |
CVE-2025-47471MEDIUM Missing Authorization vulnerability in EnvoThemes Envo Extra envo-extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envo Extra: from | May 7, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Envothemes.
Media articles that mention a CVE ID that affects a product developed by Envothemes — matched by CVE ID, not by vendor name.