WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Piotnet Addons For Elementor

Piotnet Addons For Elementor (PAFE) adds many new features for Elementor

10Reported vulnerabilities
6.4Highest CVSS score
2.4.37Latest version
30,000+Active installs

What to do now

Update Piotnet Addons For Elementor to 2.4.33 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 17, 2026 / Tested up to WordPress: 6.8.8 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-32197 Medium 6.4 0.4% 2.4.36 and earlier April 4, 2025
CVE-2024-4262 Medium 6.4 0.3% 2.4.28 and earlier 2.4.29 May 21, 2024
CVE-2024-4432 Medium 6.4 0.3% 0 to 2.4.26 (inclusive) 2.4.28 May 18, 2024
CVE-2024-33630 Medium 6.4 0.3% 2.4.27 and earlier 2.4.28 April 25, 2024
CVE-2024-29934 Medium 6.4 0.4% 2.4.25 and earlier 2.4.26 March 25, 2024
CVE-2024-13650 Medium 6.4 0.2% 0 to 2.4.36 (inclusive) April 18, 2025
CVE-2025-22333 Medium 6.4 0.2% 2.4.31 and earlier 2.4.32 January 3, 2025
CVE-2024-5502 Medium 5.4 0.3% Before 2.4.31 2.4.31 August 23, 2024
CVE-2024-5614 Medium 5.3 0.4% 0 to 2.4.29 (inclusive)
0 to 2.4.29 (inclusive)
2.4.30 July 27, 2024
CVE-2024-10775 Medium 4.3 0.3% 2.4.32 and earlier 2.4.33 January 14, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.