Plugin Vulnerability Hub
Plugin 37 known issues Latest disclosed May 21, 2026

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Vulnerabilities

Review known vulnerability records for the WordPress plugin The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce (`the-plus-addons-for-elementor-page-builder`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-5243 and CVE-2026-3311, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
37
High or Critical
0
Patch Coverage
100%
Last Updated
May 21, 2026
Related Security Guides

Use these guides while reviewing The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
36
1. Match the Package
Confirm the installed WordPress plugin slug is the-plus-addons-for-elementor-page-builder before acting on any CVE from this cluster.
2. Sort by Severity
Start with 0 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
37 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
36
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2021-4332
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6...
Vulnerability Versions up to 2.0.6 2.0.7 CVSS 6.5
CVE-2026-5243
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega...
Stored Cross-Site Scripting Versions up to 6.4.11 6.4.12 CVSS 6.4
CVE-2026-3311
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega...
Stored Cross-Site Scripting Versions up to 6.4.9 6.4.10 CVSS 6.4
CVE-2025-9698
The Plus Addons for Elementor <= 6.3.15 - Authenticated (Author+) Stored Cross-Site...
File Upload Versions up to 6.3.15 6.3.16 CVSS 6.4
CVE-2025-7646
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu...
Stored Cross-Site Scripting Versions up to 6.3.10 6.3.11 CVSS 6.4
CVE-2025-49076
The Plus Addons for Elementor Page Builder Lite <= 6.2.7 - Authenticated (Contributo...
Stored Cross-Site Scripting Versions up to 6.2.7 6.2.8 CVSS 6.4
CVE-2025-1287
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu...
Stored Cross-Site Scripting Versions up to 6.2.2 6.2.3 CVSS 6.4
CVE-2024-11829
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu...
Stored Cross-Site Scripting Versions up to 6.1.8 6.2.0 CVSS 6.4
CVE-2021-4332 Medium 2.0.7
CVE-2021-4332 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Vulnerability

The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read

CVE-2026-5243 Medium 6.4.12
CVE-2026-5243 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Stored Cross-Site Scripting

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget

CVE-2026-3311 Medium 6.4.10
CVE-2026-3311 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Stored Cross-Site Scripting

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar

CVE-2025-9698 Medium 6.3.16
CVE-2025-9698 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce File Upload

The Plus Addons for Elementor <= 6.3.15 - Authenticated (Author+) Stored Cross-Site Scripting via SVG

CVE-2025-7646 Medium 6.3.11
CVE-2025-7646 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Stored Cross-Site Scripting

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2025-49076 Medium 6.2.8
CVE-2025-49076 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Stored Cross-Site Scripting

The Plus Addons for Elementor Page Builder Lite <= 6.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2025-1287 Medium 6.2.3
CVE-2025-1287 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Stored Cross-Site Scripting

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

CVE-2024-11829 Medium 6.2.0
CVE-2024-11829 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Stored Cross-Site Scripting

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
37 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2026-5243 and CVE-2026-3311
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Medium Patch path listed

The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions...

Published
May 21, 2026
Patch Status
6.4.12
CVE-2026-5243 Medium Patch path listed

CVE-2026-5243: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hove...

Published
May 13, 2026
Patch Status
6.4.12
CVE-2026-3311 Medium Patch path listed

CVE-2026-3311: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's P...

Published
Apr 07, 2026
Patch Status
6.4.10
Known Vulnerabilities

Reports for The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes
The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions up to and including 6.4.11. The `render` function in `modules/widgets/tp_button.php` passe...

Published
May 21, 2026
Patched Release
6.4.12
Affected Versions
Versions up to 6.4.11
Next Step
Update to 6.4.12 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-5243
CVE-2026-5243: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` parameter of the Navigation Menu Lite widget in all versions up to, and including...

Published
May 13, 2026
Patched Release
6.4.12
Affected Versions
Versions up to 6.4.11
Next Step
Update to 6.4.12 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-3311
CVE-2026-3311: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Progress Bar shortcode in all versions up to, and including, 6.4.9 due to insufficient inpu...

Published
Apr 07, 2026
Patched Release
6.4.10
Affected Versions
Versions up to 6.4.9
Next Step
Update to 6.4.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-2385
CVE-2026-2385: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and tru...

Published
Feb 21, 2026
Patched Release
6.4.8
Affected Versions
Versions up to 6.4.7
Next Step
Update to 6.4.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-2386
CVE-2026-2386: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 6.4.7. This is due to the tpae_create_page() AJAX handler authorizing user...

Published
Feb 18, 2026
Patched Release
6.4.8
Affected Versions
Versions up to 6.4.7
Next Step
Update to 6.4.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-9698
CVE-2025-9698: The Plus Addons for Elementor <= 6.3.15 - Authenticated (Author+) Stored Cross-Site Scripting via SVG

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.3.15 due to insufficient input sanitization and out...

Published
Sep 22, 2025
Patched Release
6.3.16
Affected Versions
Versions up to 6.3.15
Next Step
Update to 6.3.16 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-55712
CVE-2025-55712: The Plus Addons for Elementor Page Builder Lite <= 6.3.13 - Missing Authorization

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.13. This makes it possible for...

Published
Aug 14, 2025
Patched Release
6.3.14
Affected Versions
Versions up to 6.3.13
Next Step
Update to 6.3.14 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-7646
CVE-2025-7646: The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when the user does not have th...

Published
Jul 31, 2025
Patched Release
6.3.11
Affected Versions
Versions up to 6.3.10
Next Step
Update to 6.3.11 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-49076
CVE-2025-49076: The Plus Addons for Elementor Page Builder Lite <= 6.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr...

Published
May 30, 2025
Patched Release
6.2.8
Affected Versions
Versions up to 6.2.7
Next Step
Update to 6.2.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1287
CVE-2025-1287: The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax Highlighter, and Page Scroll widgets in all versions up to, and including, 6.2.2 due t...

Published
Mar 07, 2025
Patched Release
6.2.3
Affected Versions
Versions up to 6.2.2
Next Step
Update to 6.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-11829
CVE-2024-11829: The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget's searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficien...

Published
Jan 31, 2025
Patched Release
6.2.0
Affected Versions
Versions up to 6.1.8
Next Step
Update to 6.2.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-53823
CVE-2024-53823: The Plus Addons for Elementor Page Builder Lite <= 5.6.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with cont...

Published
Dec 02, 2024
Patched Release
6.0.1
Affected Versions
Versions up to 5.6.14
Next Step
Update to 6.0.1 or newer if supported.