Title: Vulnerability
Last modified: April 24, 2025

---

# Vulnerability

 *  Resolved [igor](https://wordpress.org/support/users/igoramatuzzi/)
 * (@igoramatuzzi)
 * [1 year, 3 months ago](https://wordpress.org/support/topic/vulnerability-131/)
 * Hi! i´ve received this message from Wordfence plugin:
 * Master Addons for Elementor <= 2.0.7.5 – Authenticated (Author+) Stored Cross-
   Site Scripting
 * Description
 * The Master Addons for Elementor plugin for WordPress is vulnerable to Stored 
   Cross-Site Scripting in versions up to, and including, 2.0.7.5 due to insufficient
   input sanitization and output escaping. This makes it possible for authenticated
   attackers, with author-level access and above, to inject arbitrary web scripts
   in pages that will execute whenever a user accesses an injected page.
 * [https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-addons/master-addons-for-elementor-2066-authenticated-author-stored-cross-site-scripting](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-addons/master-addons-for-elementor-2066-authenticated-author-stored-cross-site-scripting)
 * thanks!

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Plugin Author [Liton Arefin](https://wordpress.org/support/users/litonice13/)
 * (@litonice13)
 * [1 year, 2 months ago](https://wordpress.org/support/topic/vulnerability-131/#post-18485225)
 * Hi [@igoramatuzzi](https://wordpress.org/support/users/igoramatuzzi/),
    Thanks
   for informing about the issue. We’ve contacted with patchstack and informed them
   about we’ve pushed patched for this issue. Also, we’ve pushed update with this
   issue as well. Please update the Master Addons plugin.
 * Thanks
 *  Thread Starter [igor](https://wordpress.org/support/users/igoramatuzzi/)
 * (@igoramatuzzi)
 * [1 year, 2 months ago](https://wordpress.org/support/topic/vulnerability-131/#post-18486177)
 * [@litonice13](https://wordpress.org/support/users/litonice13/) thanks a lot for
   your feedback!

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Vulnerability’ is closed to new replies.

 * ![](https://ps.w.org/master-addons/assets/icon.svg?rev=3001717)
 * [Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits](https://wordpress.org/plugins/master-addons/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/master-addons/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/master-addons/)
 * [Active Topics](https://wordpress.org/support/plugin/master-addons/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/master-addons/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/master-addons/reviews/)

 * 3 replies
 * 2 participants
 * Last reply from: [igor](https://wordpress.org/support/users/igoramatuzzi/)
 * Last activity: [1 year, 2 months ago](https://wordpress.org/support/topic/vulnerability-131/#post-18486177)
 * Status: resolved