PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)
powerpack-lite-for-elementor · plugin
Known security vulnerabilities for PowerPack Addons for Elementor (Free Widgets, Extensions and Templates). Find out in seconds which version runs on your site with WP Lens.
11 known vulnerabilities
1 exploitable without logging in · latest Mar 13, 2026
Listed on wordpress.org · latest 3.1.0 · last updated Sep 18, 2026 · 70K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Medium 6.5
CVE-2026-32430login required≤ 2.9.9
WordPress PowerPack Addons for Elementor plugin <= 2.9.9 - Cross Site Scripting (XSS) vulnerability
- Medium 6.4
CVE-2025-8388contributor+≤ 2.9.4
PowerPack Lite for Elementor <= 2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Via 'cursor_url'
- Medium 6.4
CVE-2025-1512contributor+≤ 2.9.0
PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Medium 5.4
CVE-2024-5787contributor+≤ 2.7.20
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via Link Effects Wi
- Medium 5.4
CVE-2024-5327contributor+≤ 2.7.19
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.19 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
- Medium 5.4
CVE-2024-2492contributor+≤ 2.7.18
PowerPack Addons for Elementor <= 2.7.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Tweet Widget
- Medium 5.4
CVE-2024-2491contributor+≤ 2.7.17
PowerPack Addons for Elementor <= 2.7.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via *_html_tag*
- Medium 5.4
CVE-2024-1411contributor+≤ 2.7.15
PowerPack Addons for Elementor <= 2.7.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Buttons Widget
- Medium 5.4
CVE-2024-1055contributor+≤ 2.7.14
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Medium 4.3
CVE-2023-6984unauthenticated≤ 2.7.13
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.13 - Cross-Site Request Forgery
- Medium 4.3
CVE-2024-10692contributor+≤ 2.8.1
PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.8.1 - Authenticated (Contributor+) Post Disclosure
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).