« Back to list

Elementinvader

Elementinvader Addons FOR Elementor: vulnerabilities and CVEs

Elementinvader Addons FOR Elementor has 15 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs15
Last 12 months3
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-57376High (7.1)0.25%—Jul 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This…
CVE-2026-25007High (8.5)0.25%—Mar 25, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Blind SQL…
CVE-2026-25028Medium (5.4)0.22%—Feb 3, 2026
Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…
CVE-2025-58205Medium (6.5)0.17%—Aug 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This…
CVE-2025-48288Medium (6.5)0.21%—May 19, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Stored XSS.This issue…
CVE-2025-24729Medium (5.4)0.32%—Jan 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Stored XSS.This issue…
CVE-2025-24618High (8.8)0.50%—Jan 24, 2025
Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…
CVE-2025-24578Medium (5.4)0.37%—Jan 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This…
CVE-2025-22786High (8.8)0.69%—Jan 15, 2025
Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows PHP Local File Inclusion.This issue affects ElementInvader Addons for…
CVE-2024-12059Medium (4.3)0.31%—Dec 12, 2024
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the eli_option_value shortcode. This makes it possible for…
CVE-2024-9889Medium (4.3)0.34%—Oct 19, 2024
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for…
CVE-2024-9888Medium (5.4)0.28%—Oct 16, 2024
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions up to, and including, 1.2.8 due to insufficient…
CVE-2024-47630Medium (5.4)0.26%—Oct 5, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Stored XSS.This issue…
CVE-2024-38705Medium (5.4)0.26%—Jul 20, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS.This issue affects ElementInvader Addons…
CVE-2024-2308Medium (5.4)0.32%—Mar 16, 2024
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up to, and including, 1.2.2 due to insufficient input…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services3
  2. T1005 Data from Local System2
  3. T1059.007 JavaScript1
  4. T1078 Valid Accounts1
  5. T1189 Drive-by Compromise1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Elementinvader