Sinaextra's vulnerability footprint centers on a web-page-building extension for the Elementor platform, a component that sits in the content-generation layer of WordPress sites and has meaningful prominence in that ecosystem. The recurring weaknesses—cross-site scripting, path traversal, sensitive information disclosure, and inclusion of untrusted functionality—reflect the input-handling and resource-access demands of a plugin operating within a user-editable page builder. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sinaextra over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15839HIGH The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. | Aug 30, 2019 | 7.5 | 25 | NO | NO |
CVE-2024-34384HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension for Elementor allows PHP Local File Inclusion.This issue af | Jun 4, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-49262MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shaonsina Sina Extension for Elementor sina-extension-for-elementor allows Sto | Jun 6, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-5260MEDIUM The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Store | Jul 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2021-24269MEDIUM The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as con | May 5, 2021 | 5.4 | 18 | NO | NO |
CVE-2025-1517MEDIUM The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Store | Feb 26, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-5036MEDIUM The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Store | Jun 20, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-35703MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue aff | Jun 8, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3988MEDIUM The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Store | Apr 25, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-29935MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Si | Mar 27, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sinaextra.
Media articles that mention a CVE ID that affects a product developed by Sinaextra — matched by CVE ID, not by vendor name.