Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Essential Addons for Elementor – Popular Elementor Templates & Widgets Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 64 vulnerability records associated with Essential Addons for Elementor – Popular Elementor Templates & Widgets, published between 2021 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

64Total records
2Critical
6High
56Medium
0Low
0Informational
64Patched records
0Currently marked unpatched
2021-04-13First disclosure
2026-07-20Latest disclosure
64 of 64CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202133 records
202222 records
202333 records
20243535 records
20251111 records
20261010 records

Severity Breakdown

SeverityRecordsShare
Critical23.1%
High69.4%
Medium5687.5%

Vulnerability-Type Breakdown

Cross-Site Scripting

45 records70.3%

First: 2021. Latest: 2026.

Missing Authorization

8 records12.5%

First: 2021. Latest: 2026.

Information Disclosure

6 records9.4%

First: 2023. Latest: 2025.

Other

3 records4.7%

First: 2022. Latest: 2026.

Privilege Escalation

2 records3.1%

First: 2023. Latest: 2026.

Patch Status

Patched
64
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 6.7.0
  • 6.6.11
  • 6.6.3
  • 6.6.5
  • 6.6.0
  • 6.5.10
  • 6.5.4
  • 6.5.6
  • 6.3.0
  • 6.2.3
  • 6.1.20
  • 6.0.5
  • 6.1.13
  • 6.1.10
  • 6.0.15
  • 6.0.8
  • 6.0.10
  • 6.0.4
  • 6.0.0
  • 5.9.27
  • 5.9.24
  • 5.9.23
  • 5.9.22
  • 5.9.21
  • 5.9.20
  • 5.9.18
  • 5.9.16
  • 5.9.15
  • 5.9.14
  • 5.9.12
  • 5.9.10
  • 5.9.9
  • 5.9.8
  • 5.9.5
  • 5.9.3
  • 5.8.9
  • 5.8.2
  • 5.7.2
  • 5.0.9
  • 5.0.5
  • 4.6.5
  • 4.5.4

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-5.9.8Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site ScriptingFebruary 12, 20245.9.9Medium
*-5.9.8Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site ScriptingFebruary 12, 20245.9.9Medium
*-5.9.7Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site ScriptingFebruary 1, 20245.9.8Medium
*-5.9.4Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site ScritpingJanuary 17, 20245.9.5Medium
*-5.9.4Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URlJanuary 17, 20245.9.5Medium
*-5.9.2Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site ScriptingJanuary 3, 20245.9.3Medium
*-5.8.8Essential Addons for Elementor <= 5.8.8 - Authenticated (Contributor+) Privilege EscalationSeptember 14, 20235.8.9High
*-5.8.1Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key DisclosureJuly 19, 20235.8.2Medium
*-5.7.1Essential Addons for Elementor <= 5.7.1 - Unauthenticated Arbitrary Password Reset to Privilege EscalationMay 11, 20235.7.2Critical
*-5.0.8Essential Addons for Elementor Lite <= 5.0.8 - Reflected Cross-Site ScriptingFebruary 18, 20225.0.9Medium
1.0.0-5.0.4Essential Addons for Elementor <= 5.0.4 - Local File InclusionJanuary 21, 20225.0.5Critical
*-4.6.4Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege EscalationMay 5, 20214.6.5High
*-4.6.4Essential Addons for Elementor <= 4.6.4 - Missing AuthorizationMay 5, 20214.6.5Medium
[*, 4.5.4)Essential Addons for Elementor Lite <= 4.5.3 - Cross-Site ScriptingApril 13, 20214.5.4Medium

Selected source records

Latest Records

MediumCVE-2026-15145

Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget

Published: July 20, 2026

Affected versions
*-6.6.11
Patched versions
6.7.0
Original Wordfence record
MediumCVE-2026-15156

Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings

Published: July 20, 2026

Affected versions
*-6.6.11
Patched versions
6.7.0
Original Wordfence record
HighCVE-2026-15155

Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection

Published: July 10, 2026

Affected versions
*-6.6.10
Patched versions
6.6.11
Original Wordfence record
MediumCVE-2026-6459

Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup

Published: July 7, 2026

Affected versions
*-6.6.2
Patched versions
6.6.3
Original Wordfence record
MediumCVE-2026-7665

Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler

Published: June 5, 2026

Affected versions
*-6.6.4
Patched versions
6.6.5
Original Wordfence record
MediumCVE-2026-5193

Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user

Published: May 13, 2026

Affected versions
*-6.5.13
Patched versions
6.6.0
Original Wordfence record
MediumCVE-2026-25440

Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 - Missing Authorization

Published: April 22, 2026

Affected versions
[*, 6.6.0)
Patched versions
6.6.0
Original Wordfence record
MediumCVE-2026-1512

Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget

Published: February 13, 2026

Affected versions
*-6.5.9
Patched versions
6.5.10
Original Wordfence record

Highest-Severity Records

CriticalCVE-2022-0320

Essential Addons for Elementor <= 5.0.4 - Local File Inclusion

Published: January 21, 2022

Affected versions
1.0.0-5.0.4
Patched versions
5.0.5
Original Wordfence record
CriticalCVE-2023-32243

Essential Addons for Elementor <= 5.7.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation

Published: May 11, 2023

Affected versions
*-5.7.1
Patched versions
5.7.2
Original Wordfence record
HighCVE-2024-3018

Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword

Published: March 29, 2024

Affected versions
*-5.9.13
Patched versions
5.9.14
Original Wordfence record
HighCVE-2023-41955

Essential Addons for Elementor <= 5.8.8 - Authenticated (Contributor+) Privilege Escalation

Published: September 14, 2023

Affected versions
*-5.8.8
Patched versions
5.8.9
Original Wordfence record
HighCVE-2021-4447

Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation

Published: May 5, 2021

Affected versions
*-4.6.4
Patched versions
4.6.5
Original Wordfence record
HighCVE-2026-15155

Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection

Published: July 10, 2026

Affected versions
*-6.6.10
Patched versions
6.6.11
Original Wordfence record
HighCVE-2024-8979

Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation

Published: November 14, 2024

Affected versions
*-6.0.9
Patched versions
6.0.10
Original Wordfence record
HighCVE-2024-1536

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar

Published: March 11, 2024

Affected versions
*-5.9.9
Patched versions
5.9.10
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory