Wowdevs maintains a narrowly scoped WordPress plugin ecosystem centered around Sky Addons for Elementor, a page-builder extension for the WordPress content-management platform. The recurring vulnerability classes reflect the plugin's web-facing role and integration with user-controlled content: cross-site scripting, missing authorization controls, cross-site request forgery, and exposure of sensitive information. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wowdevs over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11601HIGH The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulne | Nov 22, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-11104HIGH The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unaut | Nov 22, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-2286MEDIUM The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart) plugin for WordPress is vulnerable to Stored Cross | Mar 13, 2024 | 5.4 | 19 | NO | NO |
CVE-2025-46260MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor sky-elementor-addons allows Stored XSS.This i | Apr 24, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-38687MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor sky-elementor-addons.This issue affects Sky A | Jul 20, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-50433MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor sky-elementor-addons allows Cross-Site Script | Oct 28, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-47332MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor sky-elementor-addons allows Stored XSS.This i | Oct 6, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-9542MEDIUM The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the render function in modules/con | Nov 21, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wowdevs.
Media articles that mention a CVE ID that affects a product developed by Wowdevs — matched by CVE ID, not by vendor name.