Pricing
Case studies
Login
Start trial
Premium Addons for Elementor
Leap13
Developer
4.11.71
Latest version
700,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
36 patched
2 Mitigation rules
Authenticated (Contributor+) Stored Cross-Site Scripting via 'arrow_style' vulnerability
<= 4.10.28
02/02/2026
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Global Tooltip vulnerability
<= 4.10.31
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget vulnerability
<= 4.10.31
02/02/2026
Settings Change vulnerability
<= 4.11.63
17/01/2026
Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content' vulnerability
<= 4.11.53
31/12/2025
Cross-Site Request Forgery via 'insert_inner_template' vulnerability
<= 4.11.53
22/12/2025
Sensitive Data Exposure vulnerability
<= 4.11.53
04/12/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.69
03/07/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget vulnerability
<= 4.11.8
11/06/2025
Broken Access Control vulnerability
<= 4.10.56
19/12/2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Box Widget vulnerability
<= 4.10.60
29/10/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Media Grid Widget vulnerability
<= 4.10.52
27/09/2024
Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion and Arbitrary Title Update vulnerability
<= 4.10.38
08/08/2024
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget vulnerability
<= 4.10.36
12/07/2024
Cross Site Scripting (XSS) vulnerability
<= 4.10.34
09/07/2024
Regular Expressions Denial of Service vulnerability
<= 4.10.35
04/07/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget vulnerability
<= 4.10.35
03/07/2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 4.10.33
11/06/2024
Missing Authorization to Information Disclosure vulnerability
<= 4.10.31
31/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.31
23/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.30
30/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.28
24/04/2024
Cross Site Scripting (XSS) vulnerability
<= 4.10.25
22/04/2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.10.27
11/04/2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.10.24
11/04/2024
Authenticated DOM-Based Stored Cross-Site Scripting vulnerability
<= 4.10.24
11/04/2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.10.16
11/04/2024
Sensitive Data Exposure vulnerability
<= 4.10.22
05/04/2024
Cross Site Scripting (XSS) vulnerability
<= 4.10.16
15/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.23
14/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Banner, Team Members, and Image Scroll Widgets vulnerability
<= 4.10.21
29/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.10.18
22/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via onClick Events vulnerability
<= 4.10.18
15/02/2024
Cross Site Scripting (XSS) vulnerability
<= 4.10.16
02/02/2024
Arbitrary Blog Option Update vulnerability
<= 4.5.1
30/08/2021
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
<= 4.2.7
13/04/2021