CVE-2026-12141
- EPSS 0.19%
- Veröffentlicht 11.07.2026 03:44:24
- Zuletzt bearbeitet 14.07.2026 15:16:56
The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient inp...
CVE-2026-4790
- EPSS 0.19%
- Veröffentlicht 02.05.2026 11:16:10
- Zuletzt bearbeitet 05.05.2026 19:15:34
The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and including, 4.11.70 due to insufficient input sanitizatio...
CVE-2025-69300
- EPSS 0.21%
- Veröffentlicht 22.01.2026 16:52:31
- Zuletzt bearbeitet 27.04.2026 21:16:23
Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premium Addons for Elementor: from n/a through <= 4.11....
CVE-2025-68494
- EPSS 0.32%
- Veröffentlicht 24.12.2025 12:31:19
- Zuletzt bearbeitet 27.04.2026 19:16:25
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Premium Addons for Elementor: from...
CVE-2025-14163
- EPSS 0.16%
- Veröffentlicht 23.12.2025 09:20:01
- Zuletzt bearbeitet 08.04.2026 18:24:08
The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.11.53. This is due to missing nonce validation in the 'insert_inner_template' function. This makes it possible f...
CVE-2025-14155
- EPSS 0.78%
- Veröffentlicht 23.12.2025 09:19:59
- Zuletzt bearbeitet 08.04.2026 17:20:24
The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including,...
CVE-2024-11937
- EPSS 0.17%
- Veröffentlicht 04.07.2025 07:22:18
- Zuletzt bearbeitet 09.07.2025 17:44:13
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's linkURL in the Mobile Menu element in all versions up to, and including, 4.10.69 due to insufficient input sanitization and output esc...
CVE-2025-4774
- EPSS 0.22%
- Veröffentlicht 10.06.2025 11:22:51
- Zuletzt bearbeitet 16.07.2025 16:24:29
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdown attribute of Countdown widget in all versions up to, and including, 4.11.8 due to insufficient input sanitization and output esc...
CVE-2024-56225
- EPSS 0.31%
- Veröffentlicht 31.12.2024 11:15:08
- Zuletzt bearbeitet 23.04.2026 15:22:39
Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.56.
CVE-2024-10266
- EPSS 0.28%
- Veröffentlicht 29.10.2024 11:15:03
- Zuletzt bearbeitet 07.03.2025 14:55:48
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Box widget in all versions up to, and including, 4.10.60 due to insufficient input sanitization and output escaping on user supp...