Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesPremium Addons for Elementor

Premium Addons for Elementor vulnerabilities

Premium Addons for Elementor has 31 known vulnerabilities in this database. The most recent published record is dated 5 Oct 2026.

Known vulnerabilities
31
Active installs
600,000+
Latest version
4.11.109
Last updated
28 Sep 2026
Most recent
5 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-103084
Medium 6.5Up to 4.11.109No fixed version yet2 d ago
Cross-site scripting (XSS)
CVE-2026-12141
Medium 4.9Up to 4.11.84Fixed in a later version (latest 4.11.109)11 Jul 2026
Cross-site scripting (XSS)
CVE-2026-4790
Medium 5.4Up to 4.11.70Fixed in a later version (latest 4.11.109)2 May 2026
Broken access control
CVE-2025-14155
Medium 5.3Before 4.11.54Fixed in 4.11.5423 Dec 2025
Cross-site request forgery (CSRF)
CVE-2025-14163
Medium 4.3Before 4.11.54Fixed in 4.11.5423 Dec 2025
Cross-site scripting (XSS)
CVE-2024-11937
Medium 6.4Before 4.10.70Fixed in 4.10.704 Jul 2025
Cross-site scripting (XSS)
CVE-2025-4774
Medium 6.4Before 4.11.9Fixed in 4.11.910 Jun 2025
Cross-site scripting (XSS)
CVE-2024-10266
Medium 6.4Before 4.10.61Fixed in 4.10.6129 Oct 2024
Broken access control
CVE-2021-4445
Medium 6.5Before 4.5.2Fixed in 4.5.216 Oct 2024
Cross-site scripting (XSS)
CVE-2024-8681
Medium 6.4Before 4.10.53Fixed in 4.10.5327 Sep 2024
Broken access control
CVE-2024-6824
Medium 4.3Before 4.10.39Fixed in 4.10.398 Aug 2024
Cross-site scripting (XSS)
CVE-2024-6495
Medium 6.4Before 4.10.37Fixed in 4.10.3712 Jul 2024
Denial of service
CVE-2024-6434
Low 3.1Before 4.10.36Fixed in 4.10.364 Jul 2024
Cross-site scripting (XSS)
CVE-2024-6340
Medium 6.4Before 4.10.36Fixed in 4.10.363 Jul 2024
Cross-site scripting (XSS)
CVE-2024-5553
Medium 4.4Before 4.10.34Fixed in 4.10.3412 Jun 2024
Cross-site scripting (XSS)
CVE-2024-4376
Medium 6.4Before 4.10.32Fixed in 4.10.3231 May 2024
Cross-site scripting (XSS)
CVE-2024-4379
Medium 5.4Before 4.10.32Fixed in 4.10.3231 May 2024
Broken access control
CVE-2024-4205
Medium 4.3Before 4.10.32Fixed in 4.10.3231 May 2024
Cross-site scripting (XSS)
CVE-2024-4378
Medium 6.4Before 4.10.32Fixed in 4.10.3223 May 2024
Cross-site scripting (XSS)
CVE-2024-4203
Medium 5.4Before 4.10.31Fixed in 4.10.312 May 2024
Cross-site scripting (XSS)
CVE-2024-3885
Medium 6.4Before 4.10.29Fixed in 4.10.292 May 2024
Cross-site scripting (XSS)
CVE-2024-3647
Medium 6.4Before 4.10.29Fixed in 4.10.292 May 2024
Cross-site scripting (XSS)
CVE-2024-2665
Medium 6.4Before 4.10.28Fixed in 4.10.2810 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2666
Medium 5.4Before 4.10.25Fixed in 4.10.2510 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2664
Medium 6.4Before 4.10.25Fixed in 4.10.2510 Apr 2024
Cross-site scripting (XSS)
CVE-2024-0376
Medium 6.4Up to 4.10.16Fixed in a later version (latest 4.11.109)9 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2399
Medium 6.4Before 4.10.24Fixed in 4.10.2415 Mar 2024
Cross-site scripting (XSS)
CVE-2024-1680
Medium 6.4Before 4.10.22Fixed in 4.10.2213 Mar 2024
Cross-site scripting (XSS)
CVE-2024-0326
Medium 6.4Before 4.10.18Fixed in 4.10.1813 Mar 2024
Cross-site scripting (XSS)
CVE-2024-1242
Medium 6.4Before 4.10.19Fixed in 4.10.1929 Feb 2024
Cross-site scripting (XSS)
CVE-2021-24257
Medium 5.4Before 4.2.8Fixed in 4.2.85 May 2021
Read the published descriptions
CVE-2026-103084, 5 Oct 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.11.109. CVE record
CVE-2026-12141, 11 Jul 2026
The Premium Addons for Elementor - Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is specifically triggered when an administrator or higher-privileged user opens the affected post in the Elementor editor, as the raw unescaped output occurs via the print_template() method registered on the 'elementor/section/print_template' hook rather than on the public-facing frontend. CVE record
CVE-2026-4790, 2 May 2026
The Premium Addons for Elementor - Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and including, 4.11.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-14155, 23 Dec 2025
The Premium Addons for Elementor - Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates. CVE record
CVE-2025-14163, 23 Dec 2025
The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.11.53. This is due to missing nonce validation in the 'insert_inner_template' function. This makes it possible for unauthenticated attackers to create arbitrary Elementor templates via a forged request granted they can trick a site administrator or other user with the edit_posts capability into performing an action such as clicking on a link. CVE record
CVE-2024-11937, 4 Jul 2025
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's linkURL in the Mobile Menu element in all versions up to, and including, 4.10.69 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-4774, 10 Jun 2025
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdown attribute of Countdown widget in all versions up to, and including, 4.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-10266, 29 Oct 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Box widget in all versions up to, and including, 4.10.60 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2021-4445, 16 Oct 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and including, 4.5.1. This is due to missing capability and nonce checks in the pa_dismiss_admin_notice AJAX action. This makes it possible for authenticated subscriber+ attackers to change arbitrary options with a restricted value of 1 on vulnerable WordPress sites. CVE record
CVE-2024-8681, 27 Sep 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Grid widget in all versions up to, and including, 4.10.52 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-6824, 8 Aug 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'check_temp_validity' and 'update_template_title' functions in all versions up to, and including, 4.10.38. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary content and update post and page titles. CVE record
CVE-2024-6495, 12 Jul 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text widget in all versions up to, and including, 4.10.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-6434, 4 Jul 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possible for authenticated attackers, with Author-level access and above, to create and query a malicious post title, resulting in slowing server resources. CVE record
CVE-2024-6340, 3 Jul 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 4.10.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 4.10.36 and fully patched in version 4.10.37. CVE record
CVE-2024-5553, 12 Jun 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, 4.10.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses and edits an injected element, and subsequently clicks the element with the mouse scroll wheel. CVE record
CVE-2024-4376, 31 May 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 4.10.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. While 4.10.32 is patched, it is recommended to update to 4.10.33 because 4.10.32 caused a fatal error. CVE record
CVE-2024-4379, 31 May 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Global Tooltip widget in all versions up to, and including, 4.10.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4205, 31 May 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function in all versions up to, and including, 4.10.31. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve Elementor template data. CVE record
CVE-2024-4378, 23 May 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's menu and shape widgets in all versions up to, and including, 4.10.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4203, 2 May 2024
The Premium Addons Pro for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maps widget in all versions up to, and including, 4.10.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Please note this only affects sites running the premium version of the plugin. CVE record
CVE-2024-3885, 2 May 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the subcontainer value parameter in all versions up to, and including, 4.10.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3647, 2 May 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post ticker widget in all versions up to, and including, 4.10.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the premium version of the plugin to be installed and activated in order to be exploited. CVE record
CVE-2024-2665, 10 Apr 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button in all versions up to, and including, 4.10.27 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2666, 10 Apr 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Bullet List Widget in all versions up to, and including, 4.10.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and attempts to edit the content. CVE record
CVE-2024-2664, 10 Apr 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown Widget in all versions up to, and including, 4.10.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-0376, 9 Apr 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wrapper Link Widget in all versions up to, and including, 4.10.16 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2399, 15 Mar 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.10.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable with the premium version of the plugin is also installed. CVE record
CVE-2024-1680, 13 Mar 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Settings URL of the Banner, Team Members, and Image Scroll widgets in all versions up to, and including, 4.10.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-0326, 13 Mar 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Link Wrapper functionality in all versions up to, and including, 4.10.17 due to insufficient input sanitization and output escaping on user supplied links. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-1242, 29 Feb 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 4.10.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2021-24257, 5 May 2021
The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. CVE record

What to do if you run Premium Addons for Elementor

If you run Premium Addons for Elementor, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Premium Addons for Elementor vulnerabilities

Free. We email you when a new vulnerability is published for Premium Addons for Elementor, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support