The Plus Addons For Elementor
Vendor:
First CVE: Apr 5, 2021 · Active for 5 years
37
Total CVEs
More Total CVEs than 98% of tracked products
7.4
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact The Plus Addons For Elementor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2021
5 years ago
Most Recent CVE
Mar 8, 2025
507 days ago
CVE Severity & Scoring
The Plus Addons For Elementor37 CVEs
78%
14%
8%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network37 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (35.1%)
Unknown0 (0.0%)
Required24 (64.9%)
Privileges Required
Low29 (78.4%)
High0 (0.0%)
None8 (21.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24175CRITICAL The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated user | Apr 5, 2021 | 9.8 | 48 | NO | YES |
CVE-2021-24949CRITICAL The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL state | Jan 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-24358MEDIUM The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, lea | Jun 14, 2021 | 6.1 | 30 | NO | YES |
CVE-2021-24351MEDIUM The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected | Jun 14, 2021 | 6.1 | 30 | NO | YES |
CVE-2023-47178CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows PHP Local File Inclusio | May 17, 2024 | 9.8 | 28 | NO | NO |
CVE-2021-4331HIGH The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registrati | Mar 7, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-5455HIGH The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via the 'magazine_style' parameter | Jun 21, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-2203HIGH The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clients widget. This makes it possi | Mar 27, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-24948HIGH The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthentic | Jan 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-43932HIGH Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder.This issue affects The Plus Addons for El | Nov 1, 2024 | 8.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
8.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For The Plus Addons For Elementor
Top CWEs
Versions
No cataloged versions.