Essential Addons For Elementor
Vendor:
First CVE: May 5, 2021 · Active for 5 years
57
Total CVEs
More Total CVEs than 98% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Essential Addons For Elementor over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2021
5 years ago
Most Recent CVE
Jun 15, 2026
39 days ago
CVE Severity & Scoring
Essential Addons For Elementor57 CVEs
86%
9%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network57 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low57 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (43.9%)
Unknown0 (0.0%)
Required32 (56.1%)
Privileges Required
Low45 (78.9%)
High1 (1.8%)
None11 (19.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32243CRITICAL Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 throu | May 12, 2023 | 9.8 | 81 | NO | YES |
CVE-2025-24752MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite | Apr 17, 2025 | 6.1 | 27 | NO | YES |
CVE-2023-41955HIGH Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a th | May 17, 2024 | 8.8 | 27 | NO | NO |
CVE-2022-0320CRITICAL The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthent | Feb 1, 2022 | 9.8 | 27 | NO | NO |
CVE-2021-4447HIGH The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a | Oct 16, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-3018HIGH The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input fr | Mar 30, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-32245HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Essential Addons for Elementor Pro.This issue affects Essential Addons for Elementor Pro: from n/a through 5.4.8. | Nov 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-0683MEDIUM The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the | Feb 24, 2022 | 6.1 | 22 | NO | NO |
CVE-2026-25440MEDIUM Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. | Jun 15, 2026 | 5.3 | 21 | NO | NO |
CVE-2025-69092MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite | Dec 30, 2025 | 6.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (57 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
3.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (57 CVEs).
Media Mentions
Signals from CVEs in this product scope (57 CVEs).
Top CNAs Publishing CVEs For Essential Addons For Elementor
Top CWEs
Versions
No cataloged versions.