Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Premium Addons for Elementor
Leap13
Developer
4.11.47
Latest version
700,000
Installations
7 hours ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
29 fixed
2 Mitigation rules
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.69
Jul 3, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget vulnerability
<= 4.11.8
Jun 11, 2025
Broken Access Control vulnerability
<= 4.10.56
Dec 19, 2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Box Widget vulnerability
<= 4.10.60
Oct 29, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Media Grid Widget vulnerability
<= 4.10.52
Sep 27, 2024
Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion and Arbitrary Title Update vulnerability
<= 4.10.38
Aug 8, 2024
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget vulnerability
<= 4.10.36
Jul 12, 2024
Cross Site Scripting (XSS) vulnerability
<= 4.10.34
Jul 9, 2024
Regular Expressions Denial of Service vulnerability
<= 4.10.35
Jul 4, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget vulnerability
<= 4.10.35
Jul 3, 2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 4.10.33
Jun 11, 2024
Missing Authorization to Information Disclosure vulnerability
<= 4.10.31
May 31, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.31
May 23, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.30
Apr 30, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.28
Apr 24, 2024
Cross Site Scripting (XSS) vulnerability
<= 4.10.25
Apr 22, 2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.10.27
Apr 11, 2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.10.24
Apr 11, 2024
Authenticated DOM-Based Stored Cross-Site Scripting vulnerability
<= 4.10.24
Apr 11, 2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.10.16
Apr 11, 2024
Sensitive Data Exposure vulnerability
<= 4.10.22
Apr 5, 2024
Cross Site Scripting (XSS) vulnerability
<= 4.10.16
Mar 15, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.23
Mar 14, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Banner, Team Members, and Image Scroll Widgets vulnerability
<= 4.10.21
Feb 29, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.18
Feb 22, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via onClick Events vulnerability
<= 4.10.18
Feb 15, 2024
Cross Site Scripting (XSS) vulnerability
<= 4.10.16
Feb 2, 2024
Arbitrary Blog Option Update vulnerability
<= 4.5.1
Aug 30, 2021
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
<= 4.2.7
Apr 13, 2021