Nicheaddons develops a focused line of WordPress and Elementor page-builder add-ons targeting niche markets including events, restaurants, education, and charity sectors. The vendor's vulnerability portfolio, while modest in scale, concentrates on application-layer input-handling and authorization issues, particularly cross-site scripting, authorization bypass, and access-control weaknesses that are characteristic of web-extension plugins operating within shared WordPress ecosystems. These weakness classes reflect the challenges of sanitizing user input and enforcing role-based access in plugin contexts where multiple tenants or user roles may interact with the same underlying data. Defenders deploying these add-ons should prioritize patch application for the authorization and scripting classes named above, as they recur across the vendor's product line. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nicheaddons over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47826CRITICAL Missing Authorization vulnerability in NicheAddons Restaurant & Cafe Addon for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects | Dec 9, 2024 | 9.8 | 25 | NO | NO |
CVE-2025-8150MEDIUM The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter and Countdown widgets in all versions up to, and includ | Aug 29, 2025 | 6.4 | 22 | NO | NO |
CVE-2023-47827HIGH Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Events Addon for | Nov 30, 2023 | 7.5 | 20 | NO | NO |
CVE-2024-5229MEDIUM The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 1.5.5 | May 25, 2024 | 6.4 | 19 | NO | NO |
CVE-2024-51585MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Sales Page Addon – Elementor & Beaver Builder sales-page-addon all | Nov 9, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-44033MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Primary Addon for Elementor primary-addon-for-elementor allows Sto | Oct 6, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-44032MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-el | Oct 6, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-44026MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Charity Addon for Elementor charity-addon-for-elementor allows Sto | Oct 6, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-51581MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-el | Nov 10, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-49264MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Events Addon for Elementor events-addon-for-elementor allows Store | Oct 17, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nicheaddons.
Media articles that mention a CVE ID that affects a product developed by Nicheaddons — matched by CVE ID, not by vendor name.