CVE-2026-25440
- EPSS 0.21%
- Veröffentlicht 15.06.2026 20:17:32
- Zuletzt bearbeitet 15.06.2026 21:24:32
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
CVE-2026-23543
- EPSS 0.23%
- Veröffentlicht 19.02.2026 08:26:48
- Zuletzt bearbeitet 28.04.2026 16:16:06
Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a ...
CVE-2025-69092
- EPSS 0.13%
- Veröffentlicht 30.12.2025 10:47:58
- Zuletzt bearbeitet 29.01.2026 16:48:22
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elemento...
CVE-2025-64352
- EPSS 0.19%
- Veröffentlicht 31.10.2025 11:42:23
- Zuletzt bearbeitet 27.04.2026 16:16:40
Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a ...
CVE-2025-6244
- EPSS 0.17%
- Veröffentlicht 08.07.2025 01:43:46
- Zuletzt bearbeitet 09.07.2025 13:52:15
The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1....
CVE-2024-9993
- EPSS 0.17%
- Veröffentlicht 07.06.2025 11:17:51
- Zuletzt bearbeitet 14.07.2025 16:42:49
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all ver...
CVE-2024-9994
- EPSS 0.17%
- Veröffentlicht 07.06.2025 11:17:49
- Zuletzt bearbeitet 14.07.2025 16:42:29
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widg...
CVE-2025-24752
- EPSS 1.16%
- Veröffentlicht 17.04.2025 15:48:11
- Zuletzt bearbeitet 23.04.2026 15:25:26
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Reflected XSS.This issue affects Essential Addons for Elemento...
CVE-2025-39589
- EPSS 0.33%
- Veröffentlicht 16.04.2025 12:44:21
- Zuletzt bearbeitet 23.04.2026 15:29:50
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Retrieve Embedded Sensitive Data.This issue affects Essential Addons for...
CVE-2025-39590
- EPSS 0.26%
- Veröffentlicht 16.04.2025 12:44:20
- Zuletzt bearbeitet 23.04.2026 15:29:50
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: ...