Webtechstreet's vulnerability footprint is concentrated in a single WordPress plugin, the Elementor Addon Elements extension, which serves as a page-builder component for content management systems. The vendor's disclosures cluster around application-layer input and authorization weaknesses, with recurring issues centered on cross-site scripting, cross-site request forgery, missing authorization controls, and exposure of sensitive user data. Because the plugin operates within WordPress sites that may span diverse hosting and user bases, these classes of flaws can propagate across many downstream installations and affect both site operators and their visitors. Defenders deploying Elementor-dependent sites should prioritize this vendor's updates and audit for unauthorized access patterns and script injection vectors; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webtechstreet over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-47361HIGH Missing Authorization vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through <= 1 | Nov 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-1358MEDIUM The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render function. This makes it possible | Mar 13, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-2092MEDIUM The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to i | Jun 12, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-4723MEDIUM The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This | Nov 15, 2023 | 5.3 | 18 | NO | NO |
CVE-2021-24259MEDIUM The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contrib | May 5, 2021 | 5.4 | 18 | NO | NO |
CVE-2024-47366MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder all | Oct 6, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-7122MEDIUM The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due to insufficient | Aug 30, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-4401MEDIUM The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and includi | Aug 30, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-4570MEDIUM The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due to insufficient | Jun 27, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3743MEDIUM The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group, Shape Separator, Content Switcher, Info Circle and Timelin | May 2, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webtechstreet.
Media articles that mention a CVE ID that affects a product developed by Webtechstreet — matched by CVE ID, not by vendor name.