Plugin Vulnerability Hub
Plugin 28 known issues Latest disclosed Dec 13, 2025

Addon Elements for Elementor (formerly Elementor Addon Elements) Vulnerabilities

Review known vulnerability records for the WordPress plugin Addon Elements for Elementor (formerly Elementor Addon Elements) (`addon-elements-for-elementor-page-builder`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-12537, CVE-2024-13215 and CVE-2024-8902, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
28
High or Critical
1
Patch Coverage
100%
Last Updated
Dec 14, 2025
Priority CVE Quick Links

Fast paths into Addon Elements for Elementor (formerly Elementor Addon Elements) CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
26
CVE-2024-1358 High 1.13
CVE-2024-1358 Addon Elements for Elementor (formerly Elementor Addon Elements) Local File Inclusion

Elementor Addon Elements <= 1.12.12 - Directory Traversal to Local File Inclusion

CVE-2025-12537 Medium 1.14.4
CVE-2025-12537 Addon Elements for Elementor (formerly Elementor Addon Elements) Stored Cross-Site Scripting

Addon Elements for Elementor <= 1.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-47366 Medium 1.13.7
CVE-2024-47366 Addon Elements for Elementor (formerly Elementor Addon Elements) Stored Cross-Site Scripting

Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-7122 Medium 1.13.7
CVE-2024-7122 Addon Elements for Elementor (formerly Elementor Addon Elements) Stored Cross-Site Scripting

Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

CVE-2024-4401 Medium 1.13.6
CVE-2024-4401 Addon Elements for Elementor (formerly Elementor Addon Elements) Stored Cross-Site Scripting

Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via id and eae_slider_animation Parameters

CVE-2024-4570 Medium 1.13.6
CVE-2024-4570 Addon Elements for Elementor (formerly Elementor Addon Elements) Stored Cross-Site Scripting

Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-4569 Medium 1.13.6
CVE-2024-4569 Addon Elements for Elementor (formerly Elementor Addon Elements) Stored Cross-Site Scripting

Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-3743 Medium 1.13.4
CVE-2024-3743 Addon Elements for Elementor (formerly Elementor Addon Elements) Stored Cross-Site Scripting

Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Addon Elements for Elementor (formerly Elementor Addon Elements) so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
28 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 1 high severity finding.
Recent CVEs
CVE-2025-12537, CVE-2024-13215 and CVE-2024-8902
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Addon Elements for Elementor (formerly Elementor Addon Elements)

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-12537
CVE-2025-12537: Addon Elements for Elementor <= 1.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.14.3. This is due to insufficient input sanitization and output escaping on multiple widget parameters. This makes it possible for authentica...

Published
Dec 13, 2025
Patched Release
1.14.4
Affected Versions
Versions up to 1.14.3
Next Step
Update to 1.14.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13215
CVE-2024-13215: Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contr...

Published
Jan 14, 2025
Patched Release
1.14
Affected Versions
Versions up to 1.13.10
Next Step
Update to 1.14 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-8902
CVE-2024-8902: Elementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Con...

Published
Oct 11, 2024
Patched Release
1.13.9
Affected Versions
Versions up to 1.13.8
Next Step
Update to 1.13.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-47361
CVE-2024-47361: Elementor Addon Elements <= 1.13.6 - Missing Authorization

The Elementor Addon Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_refresh_insta_cache() function in versions up to, and including, 1.13.6. This makes it possible for authenticated attackers, with contribut...

Published
Sep 30, 2024
Patched Release
1.13.7
Affected Versions
Versions up to 1.13.6
Next Step
Update to 1.13.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-47366
CVE-2024-47366: Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access an...

Published
Sep 30, 2024
Patched Release
1.13.7
Affected Versions
Versions up to 1.13.6
Next Step
Update to 1.13.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-7122
CVE-2024-7122: Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

Published
Aug 29, 2024
Patched Release
1.13.7
Affected Versions
Versions up to 1.13.6
Next Step
Update to 1.13.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4401
CVE-2024-4401: Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via id and eae_slider_animation Parameters

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for au...

Published
Aug 29, 2024
Patched Release
1.13.6
Affected Versions
Versions up to 1.13.5
Next Step
Update to 1.13.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4570
CVE-2024-4570: Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con...

Published
Jun 26, 2024
Patched Release
1.13.6
Affected Versions
Versions up to 1.13.5
Next Step
Update to 1.13.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4569
CVE-2024-4569: Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con...

Published
Jun 26, 2024
Patched Release
1.13.6
Affected Versions
Versions up to 1.13.5
Next Step
Update to 1.13.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2092
CVE-2024-2092: Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Widget

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib...

Published
Jun 11, 2024
Patched Release
1.13.4
Affected Versions
Versions up to 1.13.3
Next Step
Update to 1.13.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3743
CVE-2024-3743: Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group, Shape Separator, Content Switcher, Info Circle and Timeline widgets in all versions up to, and including, 1.13.3 due to insufficient input sanitization and ou...

Published
Apr 29, 2024
Patched Release
1.13.4
Affected Versions
Versions up to 1.13.3
Next Step
Update to 1.13.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-30422
CVE-2024-30422: Elementor Addon Elements <= 1.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access an...

Published
Mar 28, 2024
Patched Release
1.13.2
Affected Versions
Versions up to 1.13.1
Next Step
Update to 1.13.2 or newer if supported.