Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Essential Addons for Elementor
WPDeveloper
Developer
6.4.0
Latest version
2,000,000
Installations
Oct 30, 2025
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
42 fixed
7 Mitigation rules
Broken Access Control vulnerability
<= 6.2.4
Sep 17, 2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items' vulnerability
<= 6.2.2
Aug 14, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets vulnerability
<= 6.1.19
Jul 7, 2025
Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget vulnerability
<= 6.1.12
Jun 9, 2025
Sensitive Data Exposure Vulnerability
<= 6.1.9
Apr 16, 2025
Cross Site Scripting (XSS) Vulnerability
<= 6.1.9
Apr 16, 2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 6.0.14
Feb 4, 2025
Cross Site Scripting (XSS) vulnerability
<= 6.0.7
Dec 18, 2024
Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation vulnerability
<= 6.0.9
Nov 14, 2024
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
<= 6.0.9
Nov 14, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 6.0.7
Nov 14, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget vulnerability
<= 6.0.3
Sep 11, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter vulnerability
<= 5.9.27
Aug 13, 2024
Cross Site Scripting (XSS) vulnerability
<= 5.9.26
Aug 1, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.23
Jun 11, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.22
Jun 6, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Feed vulnerability
<= 5.9.21
May 29, 2024
Cross Site Scripting (XSS) vulnerability
<= 5.9.15
May 17, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.20
May 14, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles' vulnerability
<= 5.9.19
May 10, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.17
May 1, 2024
Information Exposure vulnerability
<= 5.9.15
Apr 25, 2024
Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute vulnerability
<= 5.9.14
Apr 17, 2024
Authenticated (Author+) PHP Object Injection via error_resetpassword vulnerability
<= 5.9.13
Apr 1, 2024
Unauthenticated Sensitive Information Exposure vulnerability
<= 5.9.13
Apr 1, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.11
Mar 26, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar vulnerability
<= 5.9.9
Mar 12, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table vulnerability
<= 5.9.9
Mar 12, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery vulnerability
<= 5.9.8
Feb 13, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion vulnerability
<= 5.9.8
Feb 13, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.8
Feb 13, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.8
Feb 13, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.7
Feb 2, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl vulnerability
<= 5.9.4
Jan 18, 2024
Authenticated (Contributor+) Stored Cross-Site Scritping vulnerability
<= 5.9.4
Jan 18, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.2
Jan 4, 2024
Contributor+ Privilege Escalation vulnerability
<= 5.8.8
Sep 15, 2023
Unauthenticated MailChimp API Key Disclosure vulnerability
<= 5.8.1
Jul 20, 2023
Unauthenticated Privilege Escalation vulnerability
5.4.0-5.7.1
May 11, 2023
Reflected Cross-Site Scripting (XSS) vulnerability
<= 5.0.8
Feb 18, 2022
Unauthenticated Local File Inclusion (LFI) vulnerability
<= 5.0.4
Jan 31, 2022
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
<= 4.5.3
Apr 13, 2021