ElementInvader Addons for Elementor

ElementInvader Addons for Elementor has 16 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 16 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2025 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 9 of the records (56%). Other recurring categories include Missing Authorization, Authorization Bypass Through User-Controlled Key.

Every one of the 16 issues recorded for ElementInvader Addons for Elementor has a vendor fix available, so running the current release closes all known holes.

11 independent researchers contributed these findings, most of them (3) reported by João Pedro Soares de Alcântara. ElementInvader Addons for Elementor is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891027.01.2021Today15.03.20246.4ElementInvader Addons for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 15.03.202411.07.20246.4ElementInvader Addons for Elementor <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 11.07.202430.09.20246.4ElementInvader Addons for Elementor <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 30.09.202415.10.20245.4ElementInvader Addons for Elementor <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 5.4 · 15.10.202418.10.20244.3ElementInvader Addons for Elementor <= 1.2.9 - Authenticated (Contributor+) Information Exposure CVSS 4.3 · 18.10.202411.12.20244.3ElementInvader Addons for Elementor <= 1.3.1 - Missing Authorization to Arbitrary Options Read CVSS 4.3 · 11.12.202413.01.20258.8ElementInvader Addons for Elementor <= 1.2.6 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 13.01.202524.01.20256.4ElementInvader Addons for Elementor <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 24.01.20254.3ElementInvader Addons for Elementor <= 1.3.1 - Missing Authorization CVSS 4.3 · 24.01.20256.4ElementInvader Addons for Elementor <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 24.01.202519.05.20256.4ElementInvader Addons for Elementor <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 19.05.202527.08.20256.4ElementInvader Addons for Elementor <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 27.08.202515.10.20255.8Elementinvader Addons for Elementor <= 1.4.0 - Unauthenticated Arbitrary Email Sending CVSS 5.8 · 15.10.202505.02.20264.3ElementInvader Addons for Elementor <= 1.4.1 - Missing Authorization CVSS 4.3 · 05.02.202623.03.20266.5ElementInvader Addons for Elementor <= 1.4.2 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 23.03.202607.07.20267.2ElementInvader Addons for Elementor <= 1.4.3 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 07.07.2026

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

16

Get automatic notifications for all ElementInvader Addons for Elementor vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2025-22786

ElementInvader Addons for Elementor <= 1.2.6 - Authenticated (Contributor+) Local File Inclusion

Read the full analysis

Vulnerability Records

16 records
2026-07-07 00:00CVE-2026-57376
7.2
High
Evan NRYes
2026-03-23 00:00CVE-2026-25007
6.5
Medium
Nabil IrawanYes
2026-02-05 00:00CVE-2026-25028
4.3
Medium
Legion HunterYes
2025-10-15 00:00CVE-2025-10873
5.8
Medium
Lucas Montes (NiRoX)Yes
2025-08-27 00:00CVE-2025-58205
6.4
Medium
Abu Hurayra (HurayraIIT)Yes
2025-05-19 00:00CVE-2025-48288
6.4
Medium
MichaelYes
2025-01-24 00:00CVE-2025-24729
6.4
Medium
MichaelYes
2025-01-24 00:00CVE-2025-24618
4.3
Medium
Nirmal KavaiyaYes
2025-01-24 00:00CVE-2025-24578
6.4
Medium
João Pedro Soares de AlcântaraYes
2025-01-13 00:00CVE-2025-22786
8.8
High
João Pedro Soares de AlcântaraYes
Showing 1–10 of 16 reports
ElementInvader Addons for Elementor banner
Latestv1.4.5

ElementInvader Addons for Elementor

Element Invader

Author

Element Invader

5.0(1)
100/100
Last Updated
2026-06-04 (3mo ago)
Active Installs
3,000+
Downloads
115,530
Requires WP
6.2+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2021-01-27 (6y ago)

ElementInvader Addons for Elementor we build to additionaly simplified experiance with building templates visually with Elementor. Elementor Plugin is required to use this plugin functionality, and new elements will be visible on Elementor Widget Panel. Depends on element used plugin may call third parity apis like Mailchimp, Google Maps, Open Street Maps. We specialy make attention to simplicity and performance so forget about slowdown caused by our plugin! Unique features: Simple Contact Form for Elementor with many styles options Simple Menu for Elementor with many styles options Simple Newsletter for Elementor, with Mailchimp api, email alerts for admin and export msigned maillist option. Open Street Maps for Elementor with many styling options Google Maps for Elementor with many styling options Search Form for Elementor with many styling options Pageloader great to use for header, footer and similar parts used same on all/multiple pages Blog grid Blog search If you have any idea for new interesting element or trouble please inform us via support ticket or form here: https://elementinvader.com/ We will be always happy to help you! Contact for security issues: https://elementinvader.com/ ideas@elementinvader.com

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C