Wpdeveloper
Wpdeveloper Essential Addons FOR Elementor: vulnerabilidades y CVE
Wpdeveloper Essential Addons FOR Elementor tiene 71 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE71
Últimos 12 meses17
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102394 | Media (6.5) | 0.13% | — | 1 oct 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects… |
| CVE-2026-81777 | Media (5.3) | 0.40% | — | 28 ago 2026 | Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0. |
| CVE-2026-18039 | Alta (8.1) | 0.38% | — | 14 ago 2026 | The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account… |
| CVE-2026-13345 | Media (5.3) | 0.32% | — | 30 jul 2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing… |
| CVE-2026-13344 | Media (4.8) | 0.24% | — | 30 jul 2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to… |
| CVE-2026-15145 | Media (6.4) | 0.42% | — | 21 jul 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to… |
| CVE-2026-15156 | Media (6.4) | 0.35% | — | 21 jul 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and… |
| CVE-2026-15155 | Alta (8.8) | 0.67% | — | 11 jul 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10… |
| CVE-2026-6459 | Media (6.4) | 0.32% | — | 8 jul 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due… |
| CVE-2026-25440 | Media (5.3) | 0.29% | — | 15 jun 2026 | Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. |
| CVE-2026-7665 | Media (5.3) | 0.56% | — | 6 jun 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to… |
| CVE-2026-5193 | Media (6.5) | 0.31% | — | 14 may 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role… |
| CVE-2026-1512 | Media (6.4) | 0.24% | — | 14 feb 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9… |
| CVE-2026-1004 | Media (5.3) | 0.38% | — | 16 ene 2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible… |
| CVE-2025-69092 | Media (6.5) | 0.15% | — | 30 dic 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue… |
| CVE-2025-13977 | Media (6.4) | 0.30% | — | 17 dic 2025 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This… |
| CVE-2025-64352 | Baja (2.7) | 0.23% | — | 31 oct 2025 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential… |
| CVE-2025-8451 | Media (6.4) | 0.24% | — | 15 ago 2025 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘data-gallery-items’ parameter in all versions up to, and… |
| CVE-2025-6244 | Media (5.4) | 0.18% | — | 8 jul 2025 | The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all… |
| CVE-2024-9994 | Media (5.4) | 0.20% | — | 7 jun 2025 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content… |
| CVE-2024-9993 | Media (5.4) | 0.20% | — | 7 jun 2025 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of… |
| CVE-2025-24752 | Media (6.1) | 1.2% | — | 17 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Reflected XSS.This issue… |
| CVE-2025-39590 | Media (6.5) | 0.32% | — | 16 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects… |
| CVE-2025-39589 | Media (4.3) | 0.42% | — | 16 abr 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Retrieve Embedded Sensitive Data.This… |
| CVE-2024-56063 | Media (5.4) | 0.25% | — | 31 dic 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects… |
| CVE-2024-8979 | Media (5.7) | 0.50% | — | 15 nov 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9… |
| CVE-2024-8978 | Media (5.7) | 0.47% | — | 15 nov 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9… |
| CVE-2024-8961 | Media (5.4) | 0.30% | — | 15 nov 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text’ parameter in all… |
| CVE-2021-4447 | Alta (8.8) | 0.46% | — | 16 oct 2024 | The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom… |
| CVE-2021-4446 | Media (4.3) | 0.26% | — | 16 oct 2024 | The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.