Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor has 16 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 16 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 4 critical and 0 high. 2024 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 7 of the records (44%). Other recurring categories include Deserialization Of Untrusted Data, Missing Authorization.

Every one of the 16 issues recorded for Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor has a vendor fix available, so running the current release closes all known holes.

10 independent researchers contributed these findings, most of them (3) reported by João Pedro Soares de Alcântara.

01234567891008.04.2024Today08.04.20246.4Ultimate Store Kit Elementor Addons <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 08.04.202407.05.20249.8Ultimate Store Kit Elementor Addons <= 2.0.3 - Unauthenticated PHP Object Injection CVSS 9.8 · 07.05.202416.08.20246.4Ultimate Store Kit Elementor Addons <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 16.08.202420.08.20249.8Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 - Unauthenticated PHP Object Injection CVSS 9.8 · 20.08.202427.08.20249.8Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.0.3 - Unauthenticated PHP Object Injection CVSS 9.8 · 27.08.202430.09.20246.4Ultimate Store Kit Elementor Addons <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 30.09.202419.12.20244.3Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.3.0 - Missing Authorization CVSS 4.3 · 19.12.202404.04.20256.4Ultimate Store Kit Elementor Addons <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 04.04.202517.04.20259.8Ultimate Store Kit Elementor Addons <= 2.4.0 - Unauthenticated PHP Object Injection CVSS 9.8 · 17.04.202530.04.20254.3Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.4.1 - Cross-Site Request Forgery to Limited User Meta Update CVSS 4.3 · 30.04.202522.09.20256.4Ultimate Store Kit Elementor Addons <= 2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 22.09.202530.12.20254.3Ultimate Store Kit Elementor Addons <= 2.9.4 - Missing Authorization CVSS 4.3 · 30.12.202522.07.20266.4Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 22.07.20265.3Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor <= 3.0.5 - Unauthenticated Information Exposure CVSS 5.3 · 22.07.202628.07.20265.3Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor <= 3.0.5 - Missing Authorization CVSS 5.3 · 28.07.202608.08.20265.4Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API CVSS 5.4 · 08.08.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage100%
Open

0

Fixed

16

Get automatic notifications for all Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2025-39588

Ultimate Store Kit Elementor Addons <= 2.4.0 - Unauthenticated PHP Object Injection

Read the full analysis

Vulnerability Records

16 records
2026-08-08 00:00N/A
5.4
Medium
AnonymousYes
2026-07-28 00:00CVE-2026-25403
5.3
Medium
Bao - BlueRockYes
2026-07-22 00:00CVE-2026-65503
6.4
Medium
Nguyen Ba KhanhYes
2026-07-22 00:00CVE-2026-65505
5.3
Medium
Bao - BlueRockYes
2025-12-30 00:00CVE-2025-69336
4.3
Medium
Phat RiOYes
2025-09-22 00:00CVE-2025-58017
6.4
Medium
Abu Hurayra (HurayraIIT)Yes
2025-04-30 14:30CVE-2025-2168
4.3
Medium
Peter ThaleikisYes
2025-04-17 00:00CVE-2025-39588
9.8
Critical
domiee13Yes
2025-04-04 00:00CVE-2025-32184
6.4
Medium
João Pedro Soares de AlcântaraYes
2024-12-19 00:00CVE-2025-24584
4.3
Medium
João Pedro Soares de AlcântaraYes
Showing 1–10 of 16 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C