Extension WordPress

Vulnérabilités Exclusive Addons for Elementor

Cette page rassemble les failles publiées pour Exclusive Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

29Vulnérabilités
0Critiques
29Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Exclusive Addons for Elementor

29 fiches

CVE-2026-11328 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.7.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.7.9.8

Correctif

2.7.9.9

Publication

06/07/2026

CVE-2026-57620 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.7.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.7.9.8

Correctif

2.7.9.9

Publication

26/06/2026

CVE-2025-7498 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.7.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.7.9.4

Correctif

2.7.9.5

Publication

05/08/2025

CVE-2025-4783 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.7.9.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of the Countdown Timer Widget in all versions up to, and including, 2.7.9.1 due to insufficient input sanitization and output…

Versions affectées

*-2.7.9.1

Correctif

2.7.9.2

Publication

26/05/2025

CVE-2025-48244 Moyenne · 4,4
Exclusive Addons for Elementor

Exclusive Addons Elementor <= 2.7.9 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access…

Versions affectées

*-2.7.9

Correctif

2.7.9.1

Publication

19/05/2025

CVE-2025-1571 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Image Comparison Widgets

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output…

Versions affectées

*-2.7.6

Correctif

2.7.7

Publication

27/02/2025

CVE-2024-10312 Moyenne · 4,3
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.7.4 – Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access…

Versions affectées

*-2.7.4

Correctif

2.7.5

Publication

28/10/2024

CVE-2024-49292 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons Elementor <= 2.7.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-2.7.1

Correctif

2.7.2

Publication

15/10/2024

CVE-2024-5332 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.6.9.8 – Authenticated (Contibutor+) Stored Cross-Site Scripting via Card Widget

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-2.6.9.8

Correctif

2.6.9.9

Publication

25/06/2024

CVE-2024-4618 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.6.9.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-2.6.9.6

Correctif

2.6.9.7

Publication

14/05/2024

CVE-2024-33914 Moyenne · 5,4
Exclusive Addons for Elementor

Exclusive Addons Elementor <= 2.6.9.1 – Missing Authorization to Post Duplication

The Exclusive Addons Elementor plugin for WordPress is vulnerable to unauthorized access of datadue to an insufficient capability check on the duplicate_post() function in versions up to, and including, 2.6.9.1. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.6.9.1

Correctif

2.6.9.2

Publication

29/04/2024

CVE-2024-3489 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.6.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired Title

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.6.9.4

Correctif

2.6.9.5

Publication

22/04/2024

CVE-2024-2750 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.6.9.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of the Button widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping.…

Versions affectées

*-2.6.9.3

Correctif

2.6.9.4

Publication

22/04/2024

CVE-2024-3985 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.6.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Call to Action

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Call to Action widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping on…

Versions affectées

*-2.6.9.4

Correctif

2.6.9.5

Publication

22/04/2024

CVE-2024-2503 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.6.9.2 – Authenticated(Contributor+) Stored Cross-Site Scripting via Post Grid

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid Widget in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-2.6.9.2

Correctif

2.6.9.3

Publication

15/04/2024

CVE-2024-2751 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons for Elementor <= 2.6.9.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via InfoBox

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ parameter in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.6.9.2

Correctif

2.6.9.3

Publication

15/04/2024

CVE-2024-30232 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons Elementor <= 2.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-2.6.9

Correctif

2.6.9.1

Publication

26/03/2024

CVE-2024-30177 Moyenne · 6,4
Exclusive Addons for Elementor

Exclusive Addons Elementor <= 2.6.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-2.6.8

Correctif

2.6.9

Publication

25/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités