Plugin Vulnerability Hub
Plugin 23 known issues Latest disclosed Aug 05, 2025

Exclusive Addons for Elementor Vulnerabilities

Review known vulnerability records for the WordPress plugin Exclusive Addons for Elementor (`exclusive-addons-for-elementor`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-7498, CVE-2025-4783 and CVE-2025-48244, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
23
High or Critical
0
Patch Coverage
100%
Last Updated
Aug 06, 2025
Priority CVE Quick Links

Fast paths into Exclusive Addons for Elementor CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
23
CVE-2025-7498 Medium 2.7.9.5
CVE-2025-7498 Exclusive Addons for Elementor Stored Cross-Site Scripting

Exclusive Addons for Elementor <= 2.7.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown

CVE-2025-4783 Medium 2.7.9.2
CVE-2025-4783 Exclusive Addons for Elementor Stored Cross-Site Scripting

Exclusive Addons for Elementor <= 2.7.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget

CVE-2025-1571 Medium 2.7.7
CVE-2025-1571 Exclusive Addons for Elementor Stored Cross-Site Scripting

Exclusive Addons for Elementor <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Image Comparison Widgets

CVE-2024-49292 Medium 2.7.2
CVE-2024-49292 Exclusive Addons for Elementor Stored Cross-Site Scripting

Exclusive Addons Elementor <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-5332 Medium 2.6.9.9
CVE-2024-5332 Exclusive Addons for Elementor Stored Cross-Site Scripting

Exclusive Addons for Elementor <= 2.6.9.8 - Authenticated (Contibutor+) Stored Cross-Site Scripting via Card Widget

CVE-2024-4618 Medium 2.6.9.7
CVE-2024-4618 Exclusive Addons for Elementor Stored Cross-Site Scripting

Exclusive Addons for Elementor <= 2.6.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget

CVE-2024-3489 Medium 2.6.9.5
CVE-2024-3489 Exclusive Addons for Elementor Stored Cross-Site Scripting

Exclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired Title

CVE-2024-2750 Medium 2.6.9.4
CVE-2024-2750 Exclusive Addons for Elementor Stored Cross-Site Scripting

Exclusive Addons for Elementor <= 2.6.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Exclusive Addons for Elementor so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
23 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2025-7498, CVE-2025-4783 and CVE-2025-48244
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Exclusive Addons for Elementor

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-7498
CVE-2025-7498: Exclusive Addons for Elementor <= 2.7.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...

Published
Aug 05, 2025
Patched Release
2.7.9.5
Affected Versions
Versions up to 2.7.9.4
Next Step
Update to 2.7.9.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4783
CVE-2025-4783: Exclusive Addons for Elementor <= 2.7.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of the Countdown Timer Widget in all versions up to, and including, 2.7.9.1 due to insufficient input sanitization and output escaping. This makes it possi...

Published
May 26, 2025
Patched Release
2.7.9.2
Affected Versions
Versions up to 2.7.9.1
Next Step
Update to 2.7.9.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-48244
CVE-2025-48244: Exclusive Addons Elementor <= 2.7.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access...

Published
May 19, 2025
Patched Release
2.7.9.1
Affected Versions
Versions up to 2.7.9
Next Step
Update to 2.7.9.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1571
CVE-2025-1571: Exclusive Addons for Elementor <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Image Comparison Widgets

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping on user supplied...

Published
Feb 27, 2025
Patched Release
2.7.7
Affected Versions
Versions up to 2.7.6
Next Step
Update to 2.7.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10312
CVE-2024-10312: Exclusive Addons for Elementor <= 2.7.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access...

Published
Oct 28, 2024
Patched Release
2.7.5
Affected Versions
Versions up to 2.7.4
Next Step
Update to 2.7.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-49292
CVE-2024-49292: Exclusive Addons Elementor <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access a...

Published
Oct 15, 2024
Patched Release
2.7.2
Affected Versions
Versions up to 2.7.1
Next Step
Update to 2.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5332
CVE-2024-5332: Exclusive Addons for Elementor <= 2.6.9.8 - Authenticated (Contibutor+) Stored Cross-Site Scripting via Card Widget

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po...

Published
Jun 25, 2024
Patched Release
2.6.9.9
Affected Versions
Versions up to 2.6.9.8
Next Step
Update to 2.6.9.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4618
CVE-2024-4618: Exclusive Addons for Elementor <= 2.6.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute. This makes it...

Published
May 14, 2024
Patched Release
2.6.9.7
Affected Versions
Versions up to 2.6.9.6
Next Step
Update to 2.6.9.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-33914
CVE-2024-33914: Exclusive Addons Elementor <= 2.6.9.1 - Missing Authorization to Post Duplication

The Exclusive Addons Elementor plugin for WordPress is vulnerable to unauthorized access of datadue to an insufficient capability check on the duplicate_post() function in versions up to, and including, 2.6.9.1. This makes it possible for authenticated attackers, with contributor...

Published
Apr 29, 2024
Patched Release
2.6.9.2
Affected Versions
Versions up to 2.6.9.1
Next Step
Update to 2.6.9.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3489
CVE-2024-3489: Exclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired Title

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthentic...

Published
Apr 22, 2024
Patched Release
2.6.9.5
Affected Versions
Versions up to 2.6.9.4
Next Step
Update to 2.6.9.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2750
CVE-2024-2750: Exclusive Addons for Elementor <= 2.6.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of the Button widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Published
Apr 22, 2024
Patched Release
2.6.9.4
Affected Versions
Versions up to 2.6.9.3
Next Step
Update to 2.6.9.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3985
CVE-2024-3985: Exclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call to Action

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Call to Action widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This m...

Published
Apr 22, 2024
Patched Release
2.6.9.5
Affected Versions
Versions up to 2.6.9.4
Next Step
Update to 2.6.9.5 or newer if supported.