Essential Addons For Elementor

Vendor:

First CVE: May 5, 2021 · Active for 5 years

57
Total CVEs
More Total CVEs than 98% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Essential Addons For Elementor over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2021
5 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

CVE Severity & Scoring

Essential Addons For Elementor57 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network57 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low57 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (43.9%)
Unknown0 (0.0%)
Required32 (56.1%)
Privileges Required
Low45 (78.9%)
High1 (1.8%)
None11 (19.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 throu
May 12, 20239.881NOYES
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite
Apr 17, 20256.127NOYES
Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a th
May 17, 20248.827NONO
The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthent
Feb 1, 20229.827NONO
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a
Oct 16, 20248.826NONO
The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input fr
Mar 30, 20248.825NONO
Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Essential Addons for Elementor Pro.This issue affects Essential Addons for Elementor Pro: from n/a through 5.4.8.
Nov 18, 20238.824NONO
The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the
Feb 24, 20226.122NONO
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
Jun 15, 20265.321NONO
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite
Dec 30, 20256.521NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
3.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Essential Addons For Elementor

Top CWEs

Versions

No cataloged versions.