Pricing
Case studies
Login
Start trial
Essential Addons for Elementor
WPDeveloper
Developer
6.5.13
Latest version
2,000,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
52 patched
7 Mitigation rules
Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget vulnerability
<= 6.5.9
13/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.11
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle vulnerability
<= 5.9.15
02/02/2026
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Several Widgets vulnerability
<= 5.9.19
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' vulnerability
<= 5.9.19
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget vulnerability
<= 6.0.3
02/02/2026
Cross Site Scripting (XSS) vulnerability
<= 6.5.3
06/01/2026
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library vulnerability
<= 6.0.4
31/12/2025
Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget vulnerability
<= 6.1.12
31/12/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 6.5.3
16/12/2025
Broken Access Control vulnerability
<= 6.5.5
18/11/2025
Broken Access Control vulnerability
<= 6.2.4
17/09/2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items' vulnerability
<= 6.2.2
14/08/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets vulnerability
<= 6.1.19
07/07/2025
Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget vulnerability
<= 6.1.12
09/06/2025
Sensitive Data Exposure Vulnerability
<= 6.1.9
16/04/2025
Cross Site Scripting (XSS) Vulnerability
<= 6.1.9
16/04/2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 6.0.14
04/02/2025
Cross Site Scripting (XSS) vulnerability
<= 6.0.7
18/12/2024
Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation vulnerability
<= 6.0.9
14/11/2024
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
<= 6.0.9
14/11/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 6.0.7
14/11/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget vulnerability
<= 6.0.3
11/09/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter vulnerability
<= 5.9.27
13/08/2024
Cross Site Scripting (XSS) vulnerability
<= 5.9.26
01/08/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.23
11/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.22
06/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Feed vulnerability
<= 5.9.21
29/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.20
14/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles' vulnerability
<= 5.9.19
10/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.17
01/05/2024
Information Exposure vulnerability
<= 5.9.15
25/04/2024
Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute vulnerability
<= 5.9.14
17/04/2024
Authenticated (Author+) PHP Object Injection via error_resetpassword vulnerability
<= 5.9.13
01/04/2024
Unauthenticated Sensitive Information Exposure vulnerability
<= 5.9.13
01/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.11
26/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar vulnerability
<= 5.9.9
12/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table vulnerability
<= 5.9.9
12/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery vulnerability
<= 5.9.8
13/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion vulnerability
<= 5.9.8
13/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.8
13/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.8
13/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.7
02/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl vulnerability
<= 5.9.4
18/01/2024
Authenticated (Contributor+) Stored Cross-Site Scritping vulnerability
<= 5.9.4
18/01/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.2
04/01/2024
Contributor+ Privilege Escalation vulnerability
<= 5.8.8
15/09/2023
Unauthenticated MailChimp API Key Disclosure vulnerability
<= 5.8.1
20/07/2023
Unauthenticated Privilege Escalation vulnerability
5.4.0-5.7.1
11/05/2023
Reflected Cross-Site Scripting (XSS) vulnerability
<= 5.0.8
18/02/2022
Unauthenticated Local File Inclusion (LFI) vulnerability
<= 5.0.4
31/01/2022
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
<= 4.5.3
13/04/2021