Extension WordPress
Vulnérabilités Essential Addons for Elementor – Popular Elementor Templates & Widgets
Cette page rassemble les failles publiées pour Essential Addons for Elementor – Popular Elementor Templates & Widgets, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Essential Addons for Elementor – Popular Elementor Templates & Widgets
64 fiches
Essential Addons for Elementor <= 6.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and…
*-6.6.11
6.7.0
20/07/2026
Essential Addons for Elementor <= 6.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input…
*-6.6.11
6.7.0
20/07/2026
Essential Addons for Elementor <= 6.6.10 – Authenticated (Contributor+) Account Takeover via Email Header Injection
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10. This is due to insufficient server-side…
*-6.6.10
6.6.11
10/07/2026
Essential Addons for Elementor <= 6.6.2 – Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization…
*-6.6.2
6.6.3
08/07/2026
Essential Addons for Elementor <= 6.6.4 – Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts…
*-6.6.4
6.6.5
05/06/2026
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 – Authenticated (Author+) Limited Privilege Escalation via register_user
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function,…
*-6.5.13
6.6.0
13/05/2026
Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 – Missing Authorization
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 6.6.0. This makes it possible for…
[*, 6.6.0)
6.6.0
22/04/2026
Essential Addons for Elementor <= 6.5.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input…
*-6.5.9
6.5.10
13/02/2026
Essential Addons for Elementor <= 6.5.5 – Missing Authorization to Unauthenticated Sensitive Information Exposure
The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information…
*-6.5.5
6.5.6
15/01/2026
Essential Addons for Elementor <= 6.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-6.5.3
6.5.4
06/01/2026
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input…
*-6.5.3
6.5.4
16/12/2025
Essential Addons for Elementor <= 6.5.5 – Missing Authorization
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.5.5. This makes…
*-6.5.5
6.5.6
18/11/2025
Essential Addons for Elementor <= 6.2.4 – Missing Authorization
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.2.4. This makes…
*-6.2.4
6.3.0
17/09/2025
Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.2.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘data-gallery-items’ parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization…
*-6.2.2
6.2.3
14/08/2025
Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 – Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets
The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due…
*-6.1.19
6.1.20
07/07/2025
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-6.0.4
6.0.5
02/07/2025
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 – Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and…
*-6.1.12
6.1.13
06/06/2025
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 – Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to,…
*-6.1.12
6.1.13
06/06/2025
Essential Addons for Elementor <= 6.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-6.1.9
6.1.10
16/04/2025
Essential Addons for Elementor <= 6.1.9 – Authenticated (Contributor+) Information Disclosure
The Essential Addons for Elementor – Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.1.9. This makes it…
*-6.1.9
6.1.10
16/04/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.