ElementsKit Pro

ElementsKit Pro has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 9 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 6 of the records (67%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, PHP Remote File Inclusion.

Every one of the 9 issues recorded for ElementsKit Pro has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, most of them (4) reported by Webbernaut.

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

9

Get automatic notifications for all ElementsKit Pro vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-3500

ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced Toggle Widgets

Read the full analysis

Vulnerability Records

9 records
2026-08-27 00:00CVE-2026-4246
6.1
Medium
Ren VozaYes
2025-01-27 19:08CVE-2025-0321
6.4
Medium
WebbernautYes
2024-08-14 00:00CVE-2024-7064
6.4
Medium
WebbernautYes
2024-08-14 00:00CVE-2024-7063
4.3
Medium
WebbernautYes
2024-06-14 12:08CVE-2024-5263
6.4
Medium
wesley (wcraft)Yes
2024-06-13 00:00CVE-2024-4404
8.5
High
Ngô Thiên An (ancorn_)Yes
2024-05-20 00:00CVE-2024-4452
6.4
Medium
wesley (wcraft)Yes
2024-04-25 00:00CVE-2024-3500
8.8
High
WebbernautYes
2024-04-18 00:00CVE-2024-3598
6.4
Medium
Ngô Thiên An (ancorn_)Yes
Showing 1–9 of 9 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C