Envo Extra

Envo Extra has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 8 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Scripting, behind 4 of the records (50%). Other recurring categories include Missing Authorization, Authorization Bypass Through User-Controlled Key.

Every one of the 8 issues recorded for Envo Extra has a vendor fix available, so running the current release closes all known holes.

7 independent researchers contributed these findings, one record each. Envo Extra is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

8

Get automatic notifications for all Envo Extra vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-66066

Envo Extra <= 1.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

8 records
Envo Extra banner
Latestv1.9.22
0.0(0)
0/100
Last Updated
2026-08-20 (24d ago)
Active Installs
20,000+
Downloads
720,301
Requires WP
4.9+
Requires PHP
5.6+
Tested up to
WP 7.1
Created
2022-10-18 (4y ago)

Envo Extra add extra features and options to free Enwoo and Envo Royal theme like widgets, WooCommerce options, Elementor and Gutenberg widgets, one click demo import and much more. Add one click demo import for EnvoThemes WooCommerce themes Credits & Copyright Kirki, Copyright (c) 2017, David Vongries/Aristeides Stathopoulos Licenses: MIT Source: https://wordpress.org/plugins/kirki/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C