Master Addons develops a narrowly scoped set of WordPress plugins and extensions, with vulnerabilities clustering around its core addon product and PrettyPhoto component. The exposure reflects the input-handling and access-control challenges common to web-facing plugin ecosystems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Master Addons over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-35660CRITICAL Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1. | Jun 9, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-33595HIGH Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1. | Apr 29, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-5542MEDIUM The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Navigation M | Jun 7, 2024 | 6.1 | 19 | NO | NO |
CVE-2025-0433MEDIUM The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t | Mar 4, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-6282MEDIUM The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-w | Sep 10, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-35702MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue af | Jun 8, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-35688MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue af | Jun 8, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-5382MEDIUM The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missi | Jun 7, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-5162MEDIUM The WordPress prettyPhoto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.2.3 due to insufficient | Jun 6, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3134MEDIUM The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title_html_t | May 16, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Master Addons.
Media articles that mention a CVE ID that affects a product developed by Master Addons — matched by CVE ID, not by vendor name.