CVE Tools

LEAP13

28 CVEs tracked since 2024. Since Mar 2024, none of them reached CISA KEV.

LEAP13 CVEs per month

Mar 2024 to Jul 2024. Point at a month, or focus the strip and use the arrow keys.
LEAP13 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-03100
2024-0460
2024-0570
2024-06null or fewer
2024-0750

Products

The products that kept showing up in LEAP13's monthly top three, with their CVEs summed over those months.

  1. Premium Addons For Elementor214 months
  2. Premium Addons For Elementor – Powerful Elementor Templates & Widgets174 months
  3. Premium Addons61 month
  4. Premium Blocks – Gutenberg Blocks For WordPress11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting LEAP13.

  1. CVE-2026-94168WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability6.5
  2. CVE-2026-94118WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) vulnerability6.5
  3. CVE-2026-12141Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter4.9
  4. CVE-2026-4790Premium Addons for Elementor <= 4.11.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_svg' Parameter5.4
  5. CVE-2025-69300WordPress Premium Addons for Elementor plugin <= 4.11.63 - Settings Change vulnerability5.4
  6. CVE-2025-68494WordPress Premium Addons for Elementor plugin <= 4.11.53 - Sensitive Data Exposure vulnerability5.3
  7. CVE-2025-14163Premium Addons for Elementor <= 4.11.53 - Cross-Site Request Forgery via 'insert_inner_template'4.3
  8. CVE-2025-14155Premium Addons for Elementor <= 4.11.53 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content'5.3
  9. CVE-2024-11937Premium Addons for Elementor <= 4.10.69 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
  10. CVE-2025-4774Premium Addons for Elementor <= 4.11.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget6.4
  11. CVE-2025-22671WordPress Disable Elementor Editor Translation plugin <= 1.0.2 - Broken Access Control vulnerability4.3
  12. CVE-2024-56245WordPress Premium Blocks plugin <= 2.1.42 - Cross Site Scripting (XSS) vulnerability6.5
  13. CVE-2024-56225WordPress Premium Addons for Elementor plugin <= 4.10.56 - Broken Access Control vulnerability5.4
  14. CVE-2024-10266Premium Addons for Elementor <= 4.10.60 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Box Widget6.4
  15. CVE-2021-4445Premium Addons for Elementor <= 4.5.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update6.5

The record

Peak rank
#76 in Mar 2024
Busiest month shown
Mar 2024, 10 CVEs
Months with a KEV entry
0 since Mar 2024
Monthly snapshots
4 since 2024
LEAP13's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store