VYPR

Athemes Addons For Elementor

by WordPress

Source repositories

CVEs (4)

  • CVE-2026-8613MedJun 10, 2026
    risk 0.42cvss 6.4epss 0.00

    The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2025-12837MedNov 8, 2025
    risk 0.42cvss 6.4epss 0.00

    The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user-supplied values. This makes it possible for…

  • CVE-2025-8149MedSep 6, 2025
    risk 0.42cvss 6.4epss 0.00

    The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2024-13547MedFeb 1, 2025
    risk 0.35cvss 6.4epss 0.00

    The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…