addonsorg has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.5 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.5
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- Drag and Drop File Upload for Elementor Forms 1
- Repeater Fields for Gravity Forms 1
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-18351Critical· 9.8The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function66CVE-2026-84293High· 7.2The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and outp…40
addonsorg vulnerabilities
CVEs affecting addonsorg, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-18351Critical· 9.8PoCThe Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type valid…
▾ Abyssaladdonsorg · Drag and Drop File Upload for Elementor FormsEPSS 0.77%via NVD
CVE-2026-84293High· 7.2The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and outp…
The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and outp…
▾ Twilightaddonsorg · Repeater Fields for Gravity FormsEPSS 0.29%via NVD