cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forexclusive-addons-for-elementor exclusive-addons-for-elementor

Direction: ascending
Jun 07, 2024

Exclusive Addons for Elementor # CVE-2024-0824

CVE, Research URL

CVE-2024-0824

Date
Jan 27, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-1414

CVE, Research URL

CVE-2024-1414

Date
Mar 13, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.1.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-2028

CVE, Research URL

CVE-2024-2028

Date
Mar 13, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 Stats Widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.1.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-32110

CVE, Research URL

CVE-2024-32110

Date
Jun 11, 2026
Research Description
Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2.
Affected versions
max 2.6.9.1.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-2751

CVE, Research URL

CVE-2024-2751

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ parameter in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.3.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2022-45067

CVE, Research URL

CVE-2022-45067

Date
Feb 03, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions.
Affected versions
max 2.6.2.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-1234

CVE, Research URL

CVE-2024-1234

Date
Mar 13, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.1.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-0823

CVE, Research URL

CVE-2024-0823

Date
Feb 06, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-2503

CVE, Research URL

CVE-2024-2503

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid Widget in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping on user supplied tags. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32557 is likely a duplicate of this issue.
Affected versions
max 2.6.9.3.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-32557

CVE, Research URL

CVE-2024-32557

Date
Apr 16, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.2.
Affected versions
max 2.6.9.3.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-1413

CVE, Research URL

CVE-2024-1413

Date
Mar 13, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.1.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-30232

CVE, Research URL

CVE-2024-30232

Date
Mar 26, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.
Affected versions
max 2.6.9.1.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-30177

CVE, Research URL

CVE-2024-30177

Date
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.8.
Affected versions
max 2.6.9.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-2750

CVE, Research URL

CVE-2024-2750

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of the Button widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.4.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-3985

CVE, Research URL

CVE-2024-3985

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Call to Action widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.5.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-33914

CVE, Research URL

CVE-2024-33914

Date
May 03, 2024
Research Description
Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.
Affected versions
max 2.6.9.2.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-3489

CVE, Research URL

CVE-2024-3489

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.6.9.5.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-4618

CVE, Research URL

CVE-2024-4618

Date
May 15, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.7.
Status
vulnerable
Jun 27, 2024

Exclusive Addons for Elementor # CVE-2024-5332

CVE, Research URL

CVE-2024-5332

Date
Jun 26, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.9.
Status
vulnerable
Oct 18, 2024

Exclusive Addons for Elementor # CVE-2024-49292

CVE, Research URL

CVE-2024-49292

Date
Oct 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor exclusive-addons-for-elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through <= 2.7.1.
Affected versions
max 2.7.2.
Status
vulnerable
Oct 29, 2024

Exclusive Addons for Elementor # CVE-2024-10312

CVE, Research URL

CVE-2024-10312

Date
Oct 29, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Affected versions
max 2.7.5.
Status
vulnerable
Mar 01, 2025

Exclusive Addons for Elementor # CVE-2025-1571

CVE, Research URL

CVE-2025-1571

Date
Feb 28, 2025
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.7.7.
Status
vulnerable
May 30, 2025

Exclusive Addons for Elementor # CVE-2025-4783

CVE, Research URL

CVE-2025-4783

Date
May 27, 2025
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of the Countdown Timer Widget in all versions up to, and including, 2.7.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.7.9.2.
Status
vulnerable
Aug 06, 2025

Exclusive Addons for Elementor # CVE-2025-7498

CVE, Research URL

CVE-2025-7498

Date
Aug 06, 2025
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.7.9.5.
Status
vulnerable
Jun 14, 2026

Exclusive Addons for Elementor # CVE-2022-47150

CVE, Research URL

CVE-2022-47150

Date
Jun 11, 2026
Research Description
Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10.
Affected versions
max 2.6.2.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2025-48244

CVE, Research URL

CVE-2025-48244

Date
May 19, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor exclusive-addons-for-elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through <= 2.7.9.
Affected versions
max 2.7.9.1.
Status
vulnerable
Jun 16, 2026

Exclusive Addons for Elementor # dd7fe52414e5f575d7168d11e342627844520b4d

Date
Jan 26, 2024
Research Description
Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9 Exclusive Addons for Elementor <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Link Anything The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.
Status
vulnerable

Exclusive Addons for Elementor # 6994d8256dec5311082b945b398189084d0126d6

Date
Jan 26, 2024
Research Description
Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9 Exclusive Addons for Elementor <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.6.9.
Status
vulnerable
Jun 30, 2026

Exclusive Addons for Elementor # CVE-2026-57620

CVE, Research URL

CVE-2026-57620

Date
Jun 26, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.
Affected versions
max 2.7.9.9.
Status
vulnerable
Jul 07, 2026

Exclusive Addons for Elementor # CVE-2026-59511

CVE, Research URL

CVE-2026-59511

Date
Jul 06, 2026
Research Description
Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.
Affected versions
max 2.8.0.
Status
vulnerable
Jul 08, 2026

Exclusive Addons for Elementor # CVE-2026-11328

CVE, Research URL

CVE-2026-11328

Date
Jul 07, 2026
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.7.9.9.
Status
vulnerable