Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 41 vulnerability records associated with The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce, published between 2021 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

41Total records
0Critical
1High
40Medium
0Low
0Informational
41Patched records
0Currently marked unpatched
2021-04-13First disclosure
2026-05-28Latest disclosure
39 of 41CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202133 records
20242424 records
202566 records
202688 records

Severity Breakdown

SeverityRecordsShare
High12.4%
Medium4097.6%

Vulnerability-Type Breakdown

Cross-Site Scripting

31 records75.6%

First: 2021. Latest: 2026.

Missing Authorization

4 records9.8%

First: 2021. Latest: 2026.

Path Traversal

3 records7.3%

First: 2021. Latest: 2024.

Information Disclosure

2 records4.9%

First: 2024. Latest: 2024.

Other

1 record2.4%

First: 2026. Latest: 2026.

Patch Status

Patched
41
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 6.4.16
  • 6.4.12
  • 6.4.10
  • 6.4.8
  • 6.3.16
  • 6.3.14
  • 6.3.11
  • 6.2.8
  • 6.2.3
  • 6.2.0
  • 6.0.1
  • 6.0.4
  • 5.6.12
  • 5.6.3
  • 5.6.2
  • 5.6.1
  • 5.5.3
  • 5.5.5
  • 5.5.0
  • 5.4.2
  • 5.4.1
  • 5.3.4
  • 4.1.10
  • 2.0.7
  • 2.0.6

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-5.5.1The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 23, 20245.5.3Medium
*-5.5.4The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contibutor+) Stored Cross-Site Scripting via Hover CardMay 23, 20245.5.5Medium
*-5.5.2The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 23, 20245.5.3Medium
*-5.5.4The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip BoxMay 23, 20245.5.5Medium
*-5.4.2The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age GateMay 6, 20245.5.0Medium
*-5.4.2The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 6, 20245.5.0Medium
*-5.4.2The Plus Addons for Elementor Page Builder Lite <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 3, 20245.5.0Medium
*-5.4.2The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom AttributesApril 25, 20245.5.0Medium
*-5.4.2The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown WidgetApril 25, 20245.5.0Medium
*-5.4.1The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Clients WidgetMarch 26, 20245.4.2Medium
*-5.4.1The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member ListingMarch 26, 20245.4.2Medium
*-5.4.0The Plus Addons for Elementor <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting Header Meta Content WidgetMarch 6, 20245.4.1Medium
*-5.3.3The Plus Addons for Elementor <= 5.3.3 - Authenticated (Contributor+) Stored Cross-Site ScriptingJanuary 30, 20245.3.4Medium
4.0-4.1.9The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File ReadApril 14, 20212.0.7, 4.1.10Medium
*-2.0.6The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File ReadApril 14, 20212.0.7, 4.1.10Medium
*-2.0.6The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege EscalationApril 14, 20212.0.7High
[*, 2.0.6)The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Authenticated Stored Cross-Site ScriptingApril 13, 20212.0.6Medium

Selected source records

Latest Records

MediumCVE-2026-9243

The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter

Published: May 28, 2026

Affected versions
*-6.4.15
Patched versions
6.4.16
Original Wordfence record
MediumCVE-2026-15285

The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
Medium

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
Medium

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
MediumCVE-2026-5243

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget

Published: May 13, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
MediumCVE-2026-3311

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar

Published: April 7, 2026

Affected versions
*-6.4.9
Patched versions
6.4.10
Original Wordfence record
MediumCVE-2026-2385

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay

Published: February 21, 2026

Affected versions
*-6.4.7
Patched versions
6.4.8
Original Wordfence record
MediumCVE-2026-2386

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'

Published: February 18, 2026

Affected versions
*-6.4.7
Patched versions
6.4.8
Original Wordfence record

Highest-Severity Records

HighCVE-2021-4331

The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation

Published: April 14, 2021

Affected versions
*-4.1.9
Patched versions
4.1.10
Affected versions
*-2.0.6
Patched versions
2.0.7
Original Wordfence record
MediumCVE-2021-4332

The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read

Published: April 14, 2021

Affected versions
*-2.0.6; 4.0-4.1.9
Patched versions
2.0.7, 4.1.10
Original Wordfence record
Medium

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
MediumCVE-2024-3718

The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip Box

Published: May 23, 2024

Affected versions
*-5.5.4
Patched versions
5.5.5
Original Wordfence record
MediumCVE-2024-4482

The Plus Addons for Elementor <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

Published: July 2, 2024

Affected versions
*-5.6.1
Patched versions
5.6.2
Original Wordfence record
MediumCVE-2024-2210

The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listing

Published: March 26, 2024

Affected versions
*-5.4.1
Patched versions
5.4.2
Original Wordfence record
MediumCVE-2026-5243

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget

Published: May 13, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record
Medium

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: May 21, 2026

Affected versions
*-6.4.11
Patched versions
6.4.12
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory