« Back to list

Wpmet

Wpmet Elementskit Elementor Addons: vulnerabilities and CVEs

Wpmet Elementskit Elementor Addons has 10 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs10
Last 12 months3
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-94500Medium (6.5)0.17%—Sep 23, 2026
Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.
CVE-2026-13393Low (3.5)0.24%—Jul 31, 2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the…
CVE-2026-13392High (7.2)0.66%—Jul 31, 2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that…
CVE-2025-3614Medium (5.4)0.27%—Jul 24, 2025
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient…
CVE-2025-4479Medium (5.4)0.25%—Jun 19, 2025
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in all versions up to, and including, 3.5.2…
CVE-2024-11180Medium (5.4)0.27%—Mar 29, 2025
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to…
CVE-2025-0968Medium (5.3)0.49%—Feb 19, 2025
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content()…
CVE-2025-1005Medium (5.4)0.36%—Feb 15, 2025
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input…
CVE-2024-8546Medium (5.4)0.44%—Sep 25, 2024
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and…
CVE-2023-6525Medium (4.8)0.43%—Mar 16, 2024
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1059.007 JavaScript1
  3. T1189 Drive-by Compromise1
  4. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Wpmet