vciy

CVEs we hold for Essential

Records whose assigning authority named Essential as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8681Essential Chat Support <= 1.0.1 - Missing Authorization to Unauthenticated Settings Reset via 'ecs_reset_settings'…essentialplugin Essential Chat Support
CVE-2026-6443Essentialplugin Plugins (Various Versions) - Injected Backdooressentialplugin WP News and Scrolling Widgets
CVE-2026-18039Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass AssignmentUnknown Essential Addons for Elementor
CVE-2026-13345Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via…Unknown Essential Addons for Elementor
CVE-2026-13344Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title TagUnknown Essential Addons for Elementor
CVE-2026-0727Accordion and Accordion Slider <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Attachment Metadata…essentialplugin Accordion and Accordion Slider
CVE-2025-67470WordPress Portfolio and Projects plugin <= 1.5.5 - Sensitive Data Exposure vulnerabilityEssential Plugin Portfolio and Projects
CVE-2025-66106WordPress Featured Post Creative plugin <= 1.5.5 - Broken Access Control vulnerabilityEssential Plugin Featured Post Creative
CVE-2025-32152WordPress Slider a SlidersPack Plugin <= 2.3 - Local File Inclusion vulnerabilityEssential Plugin Slider a SlidersPack
CVE-2025-31038WordPress Essential Breadcrumbs plugin <= 1.1.1 - CSRF to Privilege Escalation vulnerabilityEssential Breadcrumbs
CVE-2025-22305WordPress Hero Banner Ultimate plugin <= 1.4.4 - Local File Inclusion vulnerabilityEssential Plugin Hero Banner Ultimate
CVE-2025-13612Album and Image Gallery Plus Lightbox <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's…essentialplugin Album and Image Gallery Plus Lightbox
CVE-2024-5612Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.15 -…Essential Addons for Elementor Pro
CVE-2024-5595Essential Blocks < 4.7.0 - Contributor+ Stored XSSUnknown Essential Blocks
CVE-2024-53778WordPress Essential Breadcrumbs plugin <= 1.1.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerabilityEssential Breadcrumbs
CVE-2024-5086Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.14 -…Essential Addons for Elementor Pro
CVE-2024-47307WordPress Meta Slider and Carousel with Lightbox plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerabilityEssential Plugin Meta slider and carousel with lightbox
CVE-2024-4194Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Executionessentialplugin Album and Image Gallery Plus Lightbox
CVE-2024-3645Essential Addons for Elementor Pro <= 5.8.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via…Essential Addons for Elementor Pro
CVE-2024-13347Essential WP Real Estate <= 1.1.3 - Reflected XSSUnknown Essential WP Real Estate
CVE-2023-6623Essential Blocks < 4.4.3 - Unauthenticated Local File InclusionUnknown Essential Blocks
CVE-2023-6141Essential Real Estate < 4.4.0 - Subscriber+ Stored XSSUnknown Essential Real Estate
CVE-2023-6140Essential Real Estate < 4.4 - Subscriber+ Arbitrary File UploadUnknown Essential Real Estate
CVE-2023-6139Essential Real Estate < 4.4.0 - Subscriber+ Denial of Service via Arbitrary Option UpdateUnknown Essential Real Estate
CVE-2023-40200WordPress WP Logo Showcase Responsive Slider and Carousel plugin <= 3.6 - Broken Access Control vulnerabilityEssential Plugin WP Logo Showcase Responsive Slider and…
CVE-2022-46845WordPress Slider a SlidersPack plugin <= 2.0.2 - Broken Access Control vulnerabilityEssential Plugin Slider a SlidersPack
CVE-2022-3933Essential Real Estate < 3.9.6 - Reflected Cross-Site-ScriptingUnknown Essential Real Estate
CVE-2022-0683Essential Addons for Elementor Lite <= 5.0.8 Reflected Cross-Site ScriptingEssential Addons for Elementor Lite
CVE-2022-0320Essential Addons for Elementor < 5.0.5 - Unauthenticated LFIUnknown Essential Addons for Elementor
CVE-2021-24255Essential Addons for Elementor < 4.5.4 - Contributor+ Stored Cross-Site Scripting (XSS)Unknown Essential Addons for Elementor

30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.