The Plus Addons for Elementor Page Builder Pro

The Plus Addons for Elementor Page Builder Pro has 13 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 13 are fixed as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 3 high. 2021 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (23%). Other recurring categories include Missing Authorization, Open Redirect.

Every one of the 13 issues recorded for The Plus Addons for Elementor Page Builder Pro has a vendor fix available, so running the current release closes all known holes.

6 independent researchers contributed these findings, most of them (4) reported by Nicolas Vidal.

01234567891008.03.2021Today08.03.20219.8Plus Addons for Elementor Page Builder <= 4.1.6 - Authentication Bypass CVSS 9.8 · 08.03.202114.04.20218.8The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation CVSS 8.8 · 14.04.202131.05.20216.1The Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirect CVSS 6.1 · 31.05.20215.3The Plus Addons for Elementor Page Builder <= 4.1.10 - Open Redirect CVSS 5.3 · 31.05.20216.1The Plus Addons for Elementor Page Builder <= 4.1.11 - Reflected Cross-Site Scripting CVSS 6.1 · 31.05.202113.12.20217.5The Plus Addons for Elementor Pro <= 5.0.6 - Sensitive Data Disclosure CVSS 7.5 · 13.12.20219.8The Plus Addons for Elementor - Pro <= 5.0.6 - SQL Injection CVSS 9.8 · 13.12.202131.10.20239.8The Plus Addons for Elementor Pro <= 5.2.8 - Unauthenticated Local File Inclusion CVSS 9.8 · 31.10.202329.05.20246.4The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Title Widget CVSS 6.4 · 29.05.202420.06.20248.8The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 20.06.20246.1The Plus Addons for Elementor Page Builder <= 5.5.6 - Reflected Cross-Site Scripting via WP Login and Register Widget CVSS 6.1 · 20.06.202420.05.20254.3The Plus Addons for Elementor Pro <= 6.3.6 - Missing Authorization CVSS 4.3 · 20.05.202516.07.20254.3The Plus Addons for Elementor Pro < 6.3.7 - Missing Authorization CVSS 4.3 · 16.07.2025

Strategic Overview

Avg CVSSHigh
7.2/ 10
Patch Coverage100%
Open

0

Fixed

13

Get automatic notifications for all The Plus Addons for Elementor Page Builder Pro vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2023-47178

The Plus Addons for Elementor Pro <= 5.2.8 - Unauthenticated Local File Inclusion

Read the full analysis

Vulnerability Records

13 records
2025-07-16 00:00CVE-2025-46434
4.3
Medium
Rafie MuhammadYes
2025-05-20 00:00CVE-2025-46259
4.3
Medium
Rafie MuhammadYes
2024-06-20 14:04CVE-2024-5344
6.1
Medium
wesley (wcraft)Yes
2024-06-20 00:00CVE-2024-5455
8.8
High
wesley (wcraft)Yes
2024-05-29 17:11CVE-2024-5341
6.4
Medium
wesley (wcraft)Yes
2023-10-31 00:00CVE-2023-47178
9.8
Critical
Rafie MuhammadYes
2021-12-13 00:00CVE-2021-24948
7.5
High
Nicolas VidalYes
2021-12-13 00:00CVE-2021-24949
9.8
Critical
Nicolas VidalYes
2021-05-31 00:00CVE-2021-24358
6.1
Medium
Nicolas VidalYes
2021-05-31 00:00CVE-2021-24359
5.3
Medium
Nicolas VidalYes
Showing 1–10 of 13 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C