Wpmet
Wpmet Elementskit Elementor Addons: vulnerabilities and CVEs
Wpmet Elementskit Elementor Addons has 10 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months3
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94500 | Medium (6.5) | 0.17% | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. |
| CVE-2026-13393 | Low (3.5) | 0.24% | — | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the… |
| CVE-2026-13392 | High (7.2) | 0.66% | — | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that… |
| CVE-2025-3614 | Medium (5.4) | 0.27% | — | Jul 24, 2025 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient… |
| CVE-2025-4479 | Medium (5.4) | 0.25% | — | Jun 19, 2025 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in all versions up to, and including, 3.5.2… |
| CVE-2024-11180 | Medium (5.4) | 0.27% | — | Mar 29, 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to… |
| CVE-2025-0968 | Medium (5.3) | 0.49% | — | Feb 19, 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content()… |
| CVE-2025-1005 | Medium (5.4) | 0.36% | — | Feb 15, 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input… |
| CVE-2024-8546 | Medium (5.4) | 0.44% | — | Sep 25, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and… |
| CVE-2023-6525 | Medium (4.8) | 0.43% | — | Mar 16, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by Wpmet
Metform Elementor Contact Form Builder · 23Elements KIT Elementor Addons · 14Elementskit · 11WP Ultimate Review · 10Fundengine · 8Gutenkit · 7WP Social Login AND Register Social Counter · 5Elementskit Elementor Addons Lite · 2Elementskit Lite · 2WP Fundraising Donation AND Crowdfunding Platform · 1Shopengine · 1Metform · 1