PoC Archive PoC Archive

tag

Elementor

High
WordPress HT Mega (Absolute Addons for Elementor) Unauthenticated PII Disclosure (CVE-2026-4106)
CVE-2026-4106· HT Mega – Absolute Addons for Elementor (WordPress plugin) unpatched
Critical
Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885· Piotnet Addons for Elementor Pro (WordPress plugin) unpatched
Critical
LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
CVE-2026-0920· LA-Studio Element Kit for Elementor (WordPress plugin, slug lakit) unpatched
High
Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691· "Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms" WordPress plugin unpatched
Medium
ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600· ElementsKit Elementor Addons (WordPress plugin) patched
High
Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
CVE-2026-9018· Easy Elements for Elementor – Addons & Website Templates (easy-elements WordPress plugin) patched