SecAlerts
e

elementskit

Security Risk Profile

34
/100
low

Security Risk Score

Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 28, 2025 to present

10
Total CVEs
0
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
34/100
low
📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
0
Medium
9
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
XSS
8

Most Affected Products

1. Wpmet Elementskit Elementor Addons Wordpress5
2. ElementsKit ElementsKit Elementor addons3
3. ElementsKit ElementsKit Pro2
4. ElementsKit Elementor addons2
5. ElementsKit ElementsKit Elementor Addons and Templates1

Recent Vulnerabilities

See more →
CVE-2026-4246
CVSS 6.1medium

ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter

Aug 28, 2026🔧 No Patch
CVE-2026-13393
CVSS 3.5low

ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)

Jul 31, 2026🔧 No Patch
CVE-2026-4362
CVSS 6.5medium

ElementsKit Elementor Addons <= 3.8.2 - Missing Authorization to Unauthenticated Widget Content Overwrite

May 5, 2026🔧 No Patch
CVE-2026-2600
CVSS 6.4medium

ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget

Apr 4, 2026🔧 No Patch
CVE-2025-3614
CVSS 6.4medium

ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget

Jul 24, 2025🔧 No Patch
CVE-2025-4479
CVSS 6.4medium

ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget

Jun 19, 2025
CVE-2024-11180
CVSS 6.4medium

ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 29, 2025
CVE-2025-0968
CVSS 5.3medium

ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function

Feb 19, 2025
CVE-2025-1005
CVSS 6.4medium

ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget

Feb 15, 2025
CVE-2025-0321
CVSS 6.4medium

ElementsKit Pro <= 3.7.8 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameter

Jan 28, 2025🔧 No Patch

Monitor elementskit in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

elementskit Security Vulnerabilities & Risk Score | 10 CVEs | SecAlerts - SecAlerts