Extension WordPress

Vulnérabilités Essential Addons for Elementor – Popular Elementor Templates & Widgets

Cette page rassemble les failles publiées pour Essential Addons for Elementor – Popular Elementor Templates & Widgets, leurs plages de versions affectées et les correctifs signalés dans la base locale.

64Vulnérabilités
2Critiques
64Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Essential Addons for Elementor – Popular Elementor Templates & Widgets

64 fiches

CVE-2026-15145 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and…

Versions affectées

*-6.6.11

Correctif

6.7.0

Publication

20/07/2026

CVE-2026-15156 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input…

Versions affectées

*-6.6.11

Correctif

6.7.0

Publication

20/07/2026

CVE-2026-15155 Élevée · 8,8
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.6.10 – Authenticated (Contributor+) Account Takeover via Email Header Injection

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10. This is due to insufficient server-side…

Versions affectées

*-6.6.10

Correctif

6.6.11

Publication

10/07/2026

CVE-2026-6459 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.6.2 – Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization…

Versions affectées

*-6.6.2

Correctif

6.6.3

Publication

08/07/2026

CVE-2026-7665 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.6.4 – Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts…

Versions affectées

*-6.6.4

Correctif

6.6.5

Publication

05/06/2026

CVE-2026-5193 Moyenne · 6,5
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 – Authenticated (Author+) Limited Privilege Escalation via register_user

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function,…

Versions affectées

*-6.5.13

Correctif

6.6.0

Publication

13/05/2026

CVE-2026-25440 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 – Missing Authorization

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 6.6.0. This makes it possible for…

Versions affectées

[*, 6.6.0)

Correctif

6.6.0

Publication

22/04/2026

CVE-2026-1512 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.5.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input…

Versions affectées

*-6.5.9

Correctif

6.5.10

Publication

13/02/2026

CVE-2026-1004 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.5.5 – Missing Authorization to Unauthenticated Sensitive Information Exposure

The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information…

Versions affectées

*-6.5.5

Correctif

6.5.6

Publication

15/01/2026

CVE-2025-69092 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-6.5.3

Correctif

6.5.4

Publication

06/01/2026

CVE-2025-13977 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input…

Versions affectées

*-6.5.3

Correctif

6.5.4

Publication

16/12/2025

CVE-2026-23543 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.5.5 – Missing Authorization

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.5.5. This makes…

Versions affectées

*-6.5.5

Correctif

6.5.6

Publication

18/11/2025

CVE-2025-64352 Moyenne · 4,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.2.4 – Missing Authorization

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.2.4. This makes…

Versions affectées

*-6.2.4

Correctif

6.3.0

Publication

17/09/2025

CVE-2025-8451 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.2.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘data-gallery-items’ parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization…

Versions affectées

*-6.2.2

Correctif

6.2.3

Publication

14/08/2025

CVE-2025-6244 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 – Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets

The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due…

Versions affectées

*-6.1.19

Correctif

6.1.20

Publication

07/07/2025

CVE-2024-5647 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

*-6.0.4

Correctif

6.0.5

Publication

02/07/2025

CVE-2024-9993 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 – Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and…

Versions affectées

*-6.1.12

Correctif

6.1.13

Publication

06/06/2025

CVE-2024-9994 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 – Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to,…

Versions affectées

*-6.1.12

Correctif

6.1.13

Publication

06/06/2025

CVE-2025-39590 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-6.1.9

Correctif

6.1.10

Publication

16/04/2025

CVE-2025-39589 Moyenne · 4,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.1.9 – Authenticated (Contributor+) Information Disclosure

The Essential Addons for Elementor – Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.1.9. This makes it…

Versions affectées

*-6.1.9

Correctif

6.1.10

Publication

16/04/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités