Wpbits develops WordPress plugins and add-ons focused on page-builder integration, with a concentrated vulnerability footprint around its Elementor extensions. The disclosed vulnerabilities cluster around cross-site scripting weaknesses stemming from improper input neutralization during page rendering, a pattern typical of server-side templating and user-generated-content scenarios in WordPress plugin ecosystems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpbits over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39703MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor al | Apr 8, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-9082MEDIUM The WPBITS Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget parameters in versions up to, and including, 1.8 due to insuff | Jan 28, 2026 | 6.4 | 21 | NO | NO |
CVE-2024-37945MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor al | Aug 14, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-22316MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor al | Jan 7, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-4862MEDIUM The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5 due to | Jul 9, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-56285MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor al | Jan 7, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-8962MEDIUM The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.2 due | Dec 4, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-32593MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBits WPBITS Addons For Elementor Page Builder allows Stored XSS.This issue a | Apr 18, 2024 | 5.4 | 15 | NO | NO |
CVE-2024-2129MEDIUM The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's heading widget in all versions up to, and including, | Mar 20, 2024 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbits.
Media articles that mention a CVE ID that affects a product developed by Wpbits — matched by CVE ID, not by vendor name.