Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 41 vulnerability records associated with The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce, published between 2021 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

41Total records
0Critical
1High
40Medium
0Low
0Informational
41Patched records
0Currently marked unpatched
2021-04-13First disclosure
2026-05-28Latest disclosure
39 of 41CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202133 records
20242424 records
202566 records
202688 records

Severity Breakdown

SeverityRecordsShare
High12.4%
Medium4097.6%

Vulnerability-Type Breakdown

Cross-Site Scripting

31 records75.6%

First: 2021. Latest: 2026.

Missing Authorization

4 records9.8%

First: 2021. Latest: 2026.

Path Traversal

3 records7.3%

First: 2021. Latest: 2024.

Information Disclosure

2 records4.9%

First: 2024. Latest: 2024.

Other

1 record2.4%

First: 2026. Latest: 2026.

Patch Status

Patched
41
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 6.4.16
  • 6.4.12
  • 6.4.10
  • 6.4.8
  • 6.3.16
  • 6.3.14
  • 6.3.11
  • 6.2.8
  • 6.2.3
  • 6.2.0
  • 6.0.1
  • 6.0.4
  • 5.6.12
  • 5.6.3
  • 5.6.2
  • 5.6.1
  • 5.5.3
  • 5.5.5
  • 5.5.0
  • 5.4.2
  • 5.4.1
  • 5.3.4
  • 4.1.10
  • 2.0.7
  • 2.0.6

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-6.4.15The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' ParameterMay 28, 20266.4.16Medium
*-6.4.11The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom AttributesMay 21, 20266.4.12Medium
*-6.4.11The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 21, 20266.4.12Medium
*-6.4.11The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 21, 20266.4.12Medium
*-6.4.11The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite WidgetMay 13, 20266.4.12Medium
*-6.4.9The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress BarApril 7, 20266.4.10Medium
*-6.4.7The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email RelayFebruary 21, 20266.4.8Medium
*-6.4.7The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'February 18, 20266.4.8Medium
*-6.3.15The Plus Addons for Elementor <= 6.3.15 - Authenticated (Author+) Stored Cross-Site Scripting via SVGSeptember 22, 20256.3.16Medium
*-6.3.13The Plus Addons for Elementor Page Builder Lite <= 6.3.13 - Missing AuthorizationAugust 14, 20256.3.14Medium
*-6.3.10The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site ScriptingJuly 31, 20256.3.11Medium
*-6.2.7The Plus Addons for Elementor Page Builder Lite <= 6.2.7 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 30, 20256.2.8Medium
*-6.2.2The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple WidgetsMarch 7, 20256.2.3Medium
*-6.1.8The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site ScriptingJanuary 31, 20256.2.0Medium
*-5.6.14The Plus Addons for Elementor Page Builder Lite <= 5.6.14 - Authenticated (Contributor+) Stored Cross-Site ScriptingDecember 2, 20246.0.1Medium
*-6.0.3The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesNovember 19, 20246.0.4Medium
*-5.6.11The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_templateOctober 10, 20245.6.12Medium
*-5.6.2The Plus Addons for Elementor Page Builder Lite <= 5.6.2 - Authenticated (Author+) Stored Cross-Site ScriptingAugust 28, 20245.6.3Medium
*-5.6.2The Plus Addons for Elementor Page Builder Lite <= 5.6.2 - Missing AuthorizationAugust 26, 20245.6.3Medium
*-5.6.2The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget SettingsAugust 21, 20245.6.3Medium
*-5.6.2The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video WidgetAugust 19, 20245.6.3Medium
*-5.6.2The Plus Addons for Elementor <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via TP Page Scroll WidgetAugust 19, 20245.6.3Medium
*-5.6.1The Plus Addons for Elementor <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown WidgetJuly 2, 20245.6.2Medium
*-5.6.0The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.0- Authenticated (Contributor+) Stored Cross-Site ScriptingJune 26, 20245.6.1Medium
*-5.5.4The Plus Addons for Elementor Page Builder Lite <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site ScriptingJune 6, 20245.5.5Medium

Selected source records

Latest Records

MediumCVE-2026-9243

The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter

Published: May 28, 2026

Affected versions
*-6.4.15
Patched versions
6.4.16
Original Wordfence record
MediumCVE-2026-15285

The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
Medium

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
Medium

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
MediumCVE-2026-5243

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget

Published: May 13, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
MediumCVE-2026-3311

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar

Published: April 7, 2026

Affected versions
*-6.4.9
Patched versions
6.4.10
Original Wordfence record
MediumCVE-2026-2385

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay

Published: February 21, 2026

Affected versions
*-6.4.7
Patched versions
6.4.8
Original Wordfence record
MediumCVE-2026-2386

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'

Published: February 18, 2026

Affected versions
*-6.4.7
Patched versions
6.4.8
Original Wordfence record

Highest-Severity Records

HighCVE-2021-4331

The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation

Published: April 14, 2021

Affected versions
*-4.1.9
Patched versions
4.1.10
Affected versions
*-2.0.6
Patched versions
2.0.7
Original Wordfence record
MediumCVE-2021-4332

The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read

Published: April 14, 2021

Affected versions
*-2.0.6; 4.0-4.1.9
Patched versions
2.0.7, 4.1.10
Original Wordfence record
Medium

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
MediumCVE-2024-3718

The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip Box

Published: May 23, 2024

Affected versions
*-5.5.4
Patched versions
5.5.5
Original Wordfence record
MediumCVE-2024-4482

The Plus Addons for Elementor <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

Published: July 2, 2024

Affected versions
*-5.6.1
Patched versions
5.6.2
Original Wordfence record
MediumCVE-2024-2210

The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listing

Published: March 26, 2024

Affected versions
*-5.4.1
Patched versions
5.4.2
Original Wordfence record
MediumCVE-2026-5243

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget

Published: May 13, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
Medium

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory