plugin

Elementor Vulnerabilities

153 known security issues reported for the Elementor WordPress plugin. Most recent disclosed Jun 29, 2026.

5 critical 6 high 80 medium

Running Elementor on your site? Check whether your installed version is affected.

Scan your site free

Elementor <= 4.1.3 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 4.1.3
Fixed in:
4.1.4
Disclosed:
Jun 29, 2026

CVE-2026-8825 on NVD →

Elementor Website Builder – more than just a page builder <= 4.1.3 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 4.1.3
Fixed in:
4.1.4
Disclosed:
Jun 25, 2026

CVE-2026-57619 on NVD →

Elementor Website Builder – more than just a page builder <= 4.1.0 - Missing Authorization

medium

The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unau...

CVSS:
4.3
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Jun 2, 2026

CVE-2026-49782 on NVD →

Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

medium

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0.4. This is due to insufficient input sanitization when processing form-encoded REST API requests. The plugin registers the _elementor_data meta field w...

CVSS:
6.4
Affected:
up to 4.0.4
Fixed in:
4.0.5
Disclosed:
Apr 30, 2026

CVE-2026-6127 on NVD →

Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

medium

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 3.35.5
Fixed in:
3.35.6
Disclosed:
Apr 7, 2026

CVE-2025-14732 on NVD →

Elementor Website Builder - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability

medium

Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability

CVSS:
4.3
Affected:
up to 3.35.7
Fixed in:
3.35.8
Disclosed:
Mar 30, 2026

Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template

medium

The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats non-published templates as readable without...

CVSS:
4.3
Affected:
up to 3.35.7
Fixed in:
3.35.8
Disclosed:
Mar 25, 2026

CVE-2026-1206 on NVD →

Elementor Website Builder < 3.35.8 - Contributor+ Sensitive Information Exposure via Elementor Template

medium
Affected:
up to 3.35.8
Fixed in:
3.35.8
Disclosed:
Mar 25, 2026

CVE-2026-1206 on NVD →

Elementor Website Builder <= 3.35.5 - Missing Authorization

medium

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.35.5. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.35.5
Fixed in:
3.35.6
Disclosed:
Mar 7, 2026

CVE-2026-32445 on NVD →

Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 3.35.5
Fixed in:
3.35.6
Disclosed:
Feb 13, 2026

CVE-2026-32352 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.33.4

unknown

[en] The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possible for authenticated attackers, w...

Affected:
up to 3.33.4
Fixed in:
3.33.4
Disclosed:
Dec 16, 2025

CVE-2025-11220 on NVD →

Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path

medium

The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possible for authenticated attackers, with c...

CVSS:
6.4
Affected:
up to 3.33.3
Fixed in:
3.33.4
Disclosed:
Dec 15, 2025

CVE-2025-11220 on NVD →

Elementor < 3.33.4 - Contributor+ Stored DOM-Based XSS via Text Path

medium
Affected:
up to 3.33.4
Fixed in:
3.33.4
Disclosed:
Dec 15, 2025

CVE-2025-11220 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] <= 3.33.0 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.33.0.

Affected:
up to 3.33.0
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67588 on NVD →

Elementor Website Builder <= 3.33.0 - Missing Authorization

medium

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.33.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an...

CVSS:
4.3
Affected:
up to 3.33.0
Fixed in:
3.33.1
Disclosed:
Nov 25, 2025

CVE-2025-67588 on NVD →

Elementor Website Builder < 3.33.1 - Missing Authorization

medium
Affected:
up to 3.33.1
Fixed in:
3.33.1
Disclosed:
Nov 25, 2025

CVE-2025-67588 on NVD →

Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import

medium

The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the...

CVSS:
4.9
Affected:
up to 3.30.2
Fixed in:
3.30.3
Disclosed:
Aug 11, 2025

CVE-2025-8081 on NVD →

Elementor < 3.30.3 - Admin+ Arbitrary File Read via Image Import

medium
Affected:
up to 3.30.3
Fixed in:
3.30.3
Disclosed:
Aug 11, 2025

CVE-2025-8081 on NVD →

Elementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...

CVSS:
6.4
Affected:
up to 3.29.0
Fixed in:
3.29.1
Disclosed:
Jul 28, 2025

CVE-2025-3075 on NVD →

Elementor <= 3.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget

medium

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
6.4
Affected:
up to 3.30.2
Fixed in:
3.30.3
Disclosed:
Jul 28, 2025

CVE-2025-4566 on NVD →

Elementor < 3.29.1 - Contributor+ Stored XSS

medium
Affected:
up to 3.29.1
Fixed in:
3.29.1
Disclosed:
Jul 28, 2025

CVE-2025-3075 on NVD →

Elementor < 3.30.3 - Contributor+ Stored XSS via Text Path Widget

medium
Affected:
up to 3.30.3
Fixed in:
3.30.3
Disclosed:
Jul 28, 2025

CVE-2025-4566 on NVD →

Elementor Website Builder <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 3.29.0
Fixed in:
3.29.1
Disclosed:
Jun 19, 2025

CVE-2024-50555 on NVD →

Elementor Website Builder < 3.29.1 - Contributor+ Stored XSS

medium
Affected:
up to 3.29.1
Fixed in:
3.29.1
Disclosed:
Jun 19, 2025

CVE-2024-50555 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.25.11 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder allows Stored XSS. This issue affects Elementor Website Builder: from n/a through 3.25.10.

Affected:
up to 3.25.11
Fixed in:
3.25.11
Disclosed:
Feb 25, 2025

CVE-2024-54444 on NVD →

Elementor Website Builder <= 3.25.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.25.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 3.25.10
Fixed in:
3.25.11
Disclosed:
Feb 24, 2025

CVE-2024-54444 on NVD →

Elementor Website Builder < 3.25.11 - Contributor+ Stored XSS

medium
Affected:
up to 3.25.11
Fixed in:
3.25.11
Disclosed:
Feb 24, 2025

CVE-2024-54444 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.27.5 (closed)

unknown

[en] The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Affected:
up to 3.27.5
Fixed in:
3.27.5
Disclosed:
Feb 20, 2025

CVE-2024-13445 on NVD →

Elementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 3.27.4
Fixed in:
3.27.5
Disclosed:
Feb 19, 2025

CVE-2024-13445 on NVD →

Elementor Website Builder < 3.27.5 - Contributor+ Stored XSS

medium
Affected:
up to 3.27.5
Fixed in:
3.27.5
Disclosed:
Feb 19, 2025

CVE-2024-13445 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.25.10 (closed)

unknown

[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...

Affected:
up to 3.25.10
Fixed in:
3.25.10
Disclosed:
Dec 21, 2024

CVE-2024-10453 on NVD →

Elementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings

medium

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible...

CVSS:
6.4
Affected:
up to 3.25.9
Fixed in:
3.25.10
Disclosed:
Dec 20, 2024

CVE-2024-10453 on NVD →

Elementor Website Builder < 3.25.10 - Contributor+ Stored XSS via Typography Settings

medium
Affected:
up to 3.25.10
Fixed in:
3.25.10
Disclosed:
Dec 20, 2024

CVE-2024-10453 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.25.8 (closed)

unknown

[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...

Affected:
up to 3.25.8
Fixed in:
3.25.8
Disclosed:
Nov 26, 2024

CVE-2024-8236 on NVD →

Elementor Website Builder – More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 3.25.7
Fixed in:
3.25.8
Disclosed:
Nov 25, 2024

CVE-2024-8236 on NVD →

Elementor Website Builder < 3.25.8 - Contributor+ Stored XSS

medium
Affected:
up to 3.25.8
Fixed in:
3.25.8
Disclosed:
Nov 25, 2024

CVE-2024-8236 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.24.6 (closed)

unknown

[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either...

Affected:
up to 3.24.6
Fixed in:
3.24.6
Disclosed:
Oct 15, 2024

CVE-2024-6757 on NVD →

Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function

medium

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excer...

CVSS:
4.3
Affected:
up to 3.24.5
Fixed in:
3.24.6
Disclosed:
Oct 14, 2024

CVE-2024-6757 on NVD →

Elementor < 3.24.6 - Contributor+ Information Exposure via get_image_alt

medium
Affected:
up to 3.24.6
Fixed in:
3.24.6
Disclosed:
Oct 14, 2024

CVE-2024-6757 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.24.0 (closed)

unknown

[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...

Affected:
up to 3.24.0
Fixed in:
3.24.0
Disclosed:
Sep 11, 2024

CVE-2024-5416 on NVD →

Elementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets

medium

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...

CVSS:
5.4
Affected:
up to 3.23.4
Fixed in:
3.24.0
Disclosed:
Sep 10, 2024

CVE-2024-5416 on NVD →

Elementor Website Builder – More than Just a Page Builder < 3.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets

medium
Affected:
up to 3.24.0
Fixed in:
3.24.0
Disclosed:
Sep 10, 2024

CVE-2024-5416 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.22.2 (closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Cross-Site Scripting (XSS), Stored XSS.This issue affects Elementor Website Builder: from n/a through 3.22.1.

Affected:
up to 3.22.2
Fixed in:
3.22.2
Disclosed:
Jul 9, 2024

CVE-2024-37437 on NVD →

Elementor Website Builder <= 3.22.1 - Authenticated (Contributor+) Arbitrary SVG Download

medium

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary SVG file download in all versions up to, and including, 3.22.1. This is due to the plugin not properly restricting access to files. This makes it possible for authenticated attackers, with contributor-level acc...

CVSS:
6.4
Affected:
up to 3.22.1
Fixed in:
3.22.2
Disclosed:
Jun 28, 2024

CVE-2024-37437 on NVD →

Elementor Website Builder < 3.22.2 - Contributor+ Arbitrary SVG Download

unknown
Affected:
up to 3.22.2
Fixed in:
3.22.2
Disclosed:
Jun 28, 2024

CVE-2024-37437 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.13.3 (closed)

unknown

[en] Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.

Affected:
up to 3.13.3
Fixed in:
3.13.3
Disclosed:
Jun 11, 2024

CVE-2023-33922 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.22.0-beta2 (closed)

unknown

[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Affected:
up to 3.22.0-beta2
Fixed in:
3.22.0-beta2
Disclosed:
May 21, 2024

CVE-2024-4619 on NVD →

Elementor Website Builder – More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 3.21.5
Fixed in:
3.21.6
Disclosed:
May 20, 2024

CVE-2024-4619 on NVD →

Elementor Website Builder < 3.21.6 - Contributor+ DOM Stored XSS

medium
Affected:
up to 3.21.6
Fixed in:
3.21.6
Disclosed:
May 20, 2024

CVE-2024-4619 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.19.1 (closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.

Affected:
up to 3.19.1
Fixed in:
3.19.1
Disclosed:
May 17, 2024

CVE-2024-24934 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.16.5 (closed)

unknown

[en] Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.

Affected:
up to 3.16.5
Fixed in:
3.16.5
Disclosed:
Apr 24, 2024

CVE-2023-47504 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.20.3 (closed)

unknown

[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attacke...

Affected:
up to 3.20.3
Fixed in:
3.20.3
Disclosed:
Apr 9, 2024

CVE-2024-2117 on NVD →

Elementor Website Builder – More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget

medium

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attackers wi...

CVSS:
6.4
Affected:
up to 3.20.2
Fixed in:
3.20.3
Disclosed:
Mar 26, 2024

CVE-2024-2117 on NVD →

Elementor Website Builder < 3.20.3 - Contributor+ DOM Stored XSS

medium
Affected:
up to 3.20.3
Fixed in:
3.20.3
Disclosed:
Mar 26, 2024

CVE-2024-2117 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.18.2 (closed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.

Affected:
up to 3.18.2
Fixed in:
3.18.2
Disclosed:
Mar 26, 2024

CVE-2023-48777 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.19.0 (closed)

unknown

[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it po...

Affected:
up to 3.19.0
Fixed in:
3.19.0
Disclosed:
Feb 20, 2024

CVE-2024-0506 on NVD →

Elementor <= 3.19.0 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization

high

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary file deletions and PHAR deserialization in version up to, and including 3.19.0. This is due to the plugin not providing sufficient path validation on the 'tmp_name' parameter . This makes it possible for authen...

CVSS:
8.8
Affected:
up to 3.19.0
Fixed in:
3.19.1
Disclosed:
Feb 7, 2024

CVE-2024-24934 on NVD →

Elementor Website Builder – More than Just a Page Builder <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt

medium

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possibl...

CVSS:
6.4
Affected:
up to 3.18.3
Fixed in:
3.19.0
Disclosed:
Feb 7, 2024

CVE-2024-0506 on NVD →

Elementor < 3.19.1 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization

critical
Affected:
up to 3.19.1
Fixed in:
3.19.1
Disclosed:
Feb 7, 2024

CVE-2024-24934 on NVD →

Elementor Website Builder – More than Just a Page Builder < 3.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt

medium
Affected:
up to 3.19.0
Fixed in:
3.19.0
Disclosed:
Feb 7, 2024

CVE-2024-0506 on NVD →

Elementor <= 3.18.1 - Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import

high

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Remote Code Execution via file upload in all versions up to and including 3.18.1 via the template import functionality. This makes it possible for authenticated attackers, with contributor-level access and above, to uplo...

CVSS:
8.8
Affected:
up to 3.18.1
Fixed in:
3.18.2
Disclosed:
Dec 6, 2023

CVE-2023-48777 on NVD →

Elementor < 3.18.2 - Contributor+ Arbitrary File Upload to RCE via Template Import

critical
Affected:
up to 3.18.2
Fixed in:
3.18.2
Disclosed:
Dec 6, 2023

CVE-2023-48777 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.16.5 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4.

Affected:
up to 3.16.5
Fixed in:
3.16.5
Disclosed:
Nov 30, 2023

CVE-2023-47505 on NVD →

Elementor Website Builder <= 3.16.4 - Missing Authorization to Arbitrary Attachment Read

medium

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_inline_svg function in all versions up to, and including, 3.16.4. This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary at...

CVSS:
6.5
Affected:
up to 3.16.4
Fixed in:
3.16.5
Disclosed:
Nov 8, 2023

CVE-2023-47504 on NVD →

Elementor Website Builder <= 3.16.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()

medium

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the get_inline_svg() function in versions up to, and including, 3.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abo...

CVSS:
6.4
Affected:
up to 3.16.4
Fixed in:
3.16.5
Disclosed:
Nov 8, 2023

CVE-2023-47505 on NVD →

Elementor Website Builder < 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()

medium
Affected:
up to 3.16.5
Fixed in:
3.16.5
Disclosed:
Nov 8, 2023

CVE-2023-47505 on NVD →

Elementor Website Builder < 3.16.5 - Missing Authorization to Arbitrary Attachment Read

medium
Affected:
up to 3.16.5
Fixed in:
3.16.5
Disclosed:
Nov 8, 2023

CVE-2023-47504 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.5.5 (closed)

unknown

[en] The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.

Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Aug 14, 2023

CVE-2022-4953 on NVD →

Elementor <= 3.5.4 - DOM-Based iFrame Injection

medium

The Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘settings’ hash parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary iframes in pages that execute...

CVSS:
6.1
Affected:
up to 3.5.4
Fixed in:
3.5.5
Disclosed:
Jul 19, 2023

CVE-2022-4953 on NVD →

Elementor < 3.5.5 - Iframe Injection

unknown
Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Jul 19, 2023

CVE-2022-4953 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.8 (closed)

unknown

[en] The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user...

Affected:
up to 2.9.8
Fixed in:
2.9.8
Disclosed:
Jun 7, 2023

CVE-2020-36703 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.12.2 (closed)

unknown

[en] The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

Affected:
up to 3.12.2
Fixed in:
3.12.2
Disclosed:
May 30, 2023

CVE-2023-0329 on NVD →

Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item

medium

The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template "save_item" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or above, to create templates with an arbitra...

CVSS:
5.4
Affected:
up to 3.13.3
Fixed in:
3.13.3
Disclosed:
May 22, 2023

CVE-2023-33922 on NVD →

Elementor <= 3.13.1 - Missing Authorization to Settings Update

medium

The Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the register_as_beta_tester(), ajax_enable_safe_mode(), ajax_get_category_items(), and ajax_re_migrate_globals() functions called via AJAX actions in versions up to, and including, 3.13.1. This make...

CVSS:
5.4
Affected:
up to 3.13.1
Fixed in:
3.13.2
Disclosed:
May 12, 2023

Elementor Website Builder < 3.13.2 - Missing Authorization

medium
Affected:
up to 3.13.2
Fixed in:
3.13.2
Disclosed:
May 12, 2023

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.13.2 (closed)

unknown

The Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the register_as_beta_tester(), ajax_enable_safe_mode(), ajax_get_category_items(), and ajax_re_migrate_globals() functions called via AJAX actions in versions up to, and including, 3.13.1. This make...

Affected:
up to 3.13.2
Fixed in:
3.13.2
Disclosed:
May 12, 2023

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.13.2 (closed)

unknown

Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.13.2). An unknown person discovered and reported this Broken Access Control vulnerability in WordPress Elementor Website Builder Plugin. This vulnerability has been fixed in version 3.13.2.

Affected:
up to 3.13.2
Fixed in:
3.13.2
Disclosed:
May 12, 2023

Elementor Website Builder < 3.12.2 - Admin+ SQLi

unknown
Affected:
up to 3.12.2
Fixed in:
3.12.2
Disclosed:
May 2, 2023

CVE-2023-0329 on NVD →

Elementor <= 3.12.1 - Authenticated(Administrator+) SQL Injection via 'replace_urls'

medium

The Elementor plugin for WordPress is vulnerable to blind SQL Injection via the 'replace_urls' functionality in versions up to, and including, 3.12.1 due to insufficient escaping on the user supplied 'old' and 'new' parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for aut...

CVSS:
6.6
Affected:
up to 3.12.2
Fixed in:
3.12.2
Disclosed:
Apr 24, 2023

CVE-2023-0329 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.12.2 (closed)

unknown

The Elementor plugin for WordPress is vulnerable to blind SQL Injection via the 'replace_urls' functionality in versions up to, and including, 3.12.1 due to insufficient escaping on the user supplied 'old' and 'new' parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for aut...

Affected:
up to 3.12.2
Fixed in:
3.12.2
Disclosed:
Apr 24, 2023

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.12.2 (closed)

unknown

Update the Elementor plugin to the latest available version (at least 3.12.2). An unknown person discovered and reported this SQL Injection vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing infor...

Affected:
up to 3.12.2
Fixed in:
3.12.2
Disclosed:
Apr 24, 2023

Elementor Website Builder <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting

medium

The Elementor Website Builder plugin for WordPress is vulnerable to Unauthenticated DOM-based Reflected Cross-Site Scripting via the ‘videoType’ and 'onError' parameter in the lightbox module in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for u...

CVSS:
6.1
Affected:
up to 3.5.5
Fixed in:
3.5.6
Disclosed:
Jun 13, 2022

CVE-2022-29455 on NVD →

Elementor < 3.5.6 - DOM Reflected Cross-Site Scripting

medium
Affected:
up to 3.5.6
Fixed in:
3.5.6
Disclosed:
Jun 13, 2022

CVE-2022-29455 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.5.6 (closed)

unknown

[en] DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.

Affected:
up to 3.5.6
Fixed in:
3.5.6
Disclosed:
Jun 13, 2022

CVE-2022-29455 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] >= 3.6.0 - <= 3.6.2 (closed)

unknown

[en] The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used...

Affected:
3.6.0 – 3.6.2
Fixed in:
3.6.2
Disclosed:
Apr 19, 2022

CVE-2022-1329 on NVD →

Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution

high

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to o...

CVSS:
8.8
Affected:
3.6.0 – 3.6.2
Fixed in:
3.6.3
Disclosed:
Apr 13, 2022

CVE-2022-1329 on NVD →

Elementor 3.6.0-3.6.2 - Subscriber+ Arbitrary File Upload

critical
Affected:
3.6.0 – 3.6.3
Fixed in:
3.6.3
Disclosed:
Apr 13, 2022

CVE-2022-1329 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.6.3 (closed)

unknown

[en] The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.

Affected:
up to 3.6.3
Fixed in:
3.6.3
Disclosed:
Nov 23, 2021

CVE-2021-24891 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

unknown

[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Apr 5, 2021

CVE-2021-24202 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

unknown

[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Apr 5, 2021

CVE-2021-24203 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

unknown

[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Apr 5, 2021

CVE-2021-24204 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

unknown

[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builde...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Apr 5, 2021

CVE-2021-24205 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

unknown

[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_buil...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Apr 5, 2021

CVE-2021-24206 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

unknown

[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Apr 5, 2021

CVE-2021-24201 on NVD →

Elementor < 3.4.8 - DOM Cross-Site-Scripting

unknown
Affected:
up to 3.4.8
Fixed in:
3.4.8
Disclosed:
Mar 24, 2021

CVE-2021-24891 on NVD →

Elementor Website Builder <= 3.4.7 - DOM-based Cross-Site Scripting

medium

The Elementor Website Builder plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the '#elementor-action:action=lightbox&settings=' DOM in versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
6.1
Affected:
0.1.0 – 3.4.7
Fixed in:
3.4.8
Disclosed:
Mar 23, 2021

CVE-2021-24891 on NVD →

Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_html_tag

medium

In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_build...

CVSS:
6.4
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24204 on NVD →

Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_size

medium

In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’...

CVSS:
6.4
Affected:
0.1.0 – 3.1.3
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24206 on NVD →

Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag

medium

In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ reque...

CVSS:
6.4
Affected:
0.1.0 – 3.1.3
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24201 on NVD →

Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_size Parameter

medium

In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ re...

CVSS:
6.4
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24205 on NVD →

Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via header_size

medium

In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ req...

CVSS:
6.4
Affected:
0.1.0 – 3.1.3
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24202 on NVD →

Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag

medium

In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ reque...

CVSS:
6.4
Affected:
0.1.0 – 3.1.3
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24203 on NVD →

Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element

medium
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24201 on NVD →

Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget

medium
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24202 on NVD →

Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget

medium
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24203 on NVD →

Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget

medium
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24204 on NVD →

Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget

medium
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24205 on NVD →

Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget

medium
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

CVE-2021-24206 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities found by WordFence in WordPress Elementor Website Builder plugin (versions <= 3.1.1).

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 17, 2021

Elementor < 3.0.14 - SVG Upload Allowed by Default

unknown
Affected:
up to 3.0.14
Fixed in:
3.0.14
Disclosed:
Jan 6, 2021

CVE-2020-36171 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.0.14 (closed)

unknown

[en] The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.

Affected:
up to 3.0.14
Fixed in:
3.0.14
Disclosed:
Jan 6, 2021

CVE-2020-36171 on NVD →

Elementor Website Builder <= 3.0.13 - Unrestricted SVG Uploads

medium

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized malicious SVG file uploads in versions up to, and including, 3.0.13. This is due to improper restrictions on allowing SVG file uploads. This makes it possible for authenticated attackers with post editor access to upload SVG files that cou...

CVSS:
6.4
Affected:
up to 3.0.13
Fixed in:
3.0.14
Disclosed:
Nov 25, 2020

CVE-2020-36171 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.3 (closed)

unknown

[en] A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Sep 16, 2020

CVE-2020-20406 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.14 (closed)

unknown

[en] An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.

Affected:
up to 2.9.14
Fixed in:
2.9.14
Disclosed:
Aug 31, 2020

CVE-2020-15020 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.6 (closed)

unknown

[en] Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

Affected:
up to 2.9.6
Fixed in:
2.9.6
Disclosed:
Aug 21, 2020

CVE-2020-20634 on NVD →

Elementor < 2.9.14 - Authenticated Stored Cross-Site Scripting

medium
Affected:
up to 2.9.14
Fixed in:
2.9.14
Disclosed:
Jul 21, 2020

CVE-2020-15020 on NVD →

Elementor Website Builder <= 2.9.13 - Authenticated Stored Cross-Site Scripting

medium

An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.

CVSS:
6.4
Affected:
up to 2.9.14
Fixed in:
2.9.14
Disclosed:
Jul 7, 2020

CVE-2020-15020 on NVD →

Elementor Website Builder <= 2.9.8 - Stored Cross-Site Scripting

medium

The Elementor Website Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.

CVSS:
5.4
Affected:
up to 2.9.8
Fixed in:
2.9.9
Disclosed:
Jun 5, 2020

CVE-2020-13864 on NVD →

Elementor Website Builder <= 2.9.8 - Stored Cross-Site Scripting

medium

The Elementor Website Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.

CVSS:
5.4
Affected:
up to 2.9.8
Fixed in:
2.9.9
Disclosed:
Jun 5, 2020

CVE-2020-13865 on NVD →

Elementor Page Builder < 2.9.10 - Authenticated Stored XSS

medium
Affected:
up to 2.9.10
Fixed in:
2.9.10
Disclosed:
Jun 5, 2020

CVE-2020-13864 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.9 (closed)

unknown

[en] The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.

Affected:
up to 2.9.9
Fixed in:
2.9.9
Disclosed:
Jun 5, 2020

CVE-2020-13864 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.10 (closed)

unknown

[en] The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.

Affected:
up to 2.9.10
Fixed in:
2.9.10
Disclosed:
Jun 5, 2020

CVE-2020-13865 on NVD →

Elementor < 2.9.8 - SVG Sanitizer Bypass leading to Authenticated Stored XSS

medium
Affected:
up to 2.9.8
Fixed in:
2.9.8
Disclosed:
May 6, 2020

CVE-2020-36703 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.7.5 (closed)

unknown

[en] An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.

Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Apr 22, 2020

CVE-2020-7055 on NVD →

Elementor Website Builder <= 2.9.7 - Authenticated Stored Cross-Site Scripting

medium

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user acce...

CVSS:
6.4
Affected:
up to 2.9.7
Fixed in:
2.9.8
Disclosed:
Apr 21, 2020

CVE-2020-36703 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.8 (closed)

unknown

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user acce...

Affected:
up to 2.9.8
Fixed in:
2.9.8
Disclosed:
Apr 21, 2020

Elementor Website Builder <= 2.9.5 - Authorization Bypass

medium

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

CVSS:
6.5
Affected:
up to 2.9.5
Fixed in:
2.9.6
Disclosed:
Mar 31, 2020

CVE-2020-20634 on NVD →

Elementor Page Builder < 2.9.6 - Authenticated Safe Mode Privilege Escalation

critical
Affected:
up to 2.9.6
Fixed in:
2.9.6
Disclosed:
Mar 31, 2020

CVE-2020-20634 on NVD →

Elementor Website Builder <= 2.9.2 - Stored Cross-Site Scripting

medium

A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.

CVSS:
6.4
Affected:
up to 2.9.2
Fixed in:
2.9.3
Disclosed:
Feb 26, 2020

CVE-2020-20406 on NVD →

Elementor Website Builder <= 2.7.5 - Stored Cross-Site Scripting

medium

The Elementor Website Builder for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.5 that makes it possible for attackers to inject arbitrary web scripts via the elementor_js_log AJAX action. This requires low-level authenticated user access to exploit.

CVSS:
6.4
Affected:
up to 2.7.5
Fixed in:
2.7.6
Disclosed:
Jan 29, 2020

Elementor Website Builder <= 2.8.4 - Reflected Cross-Site Scripting

medium

The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.

CVSS:
6.1
Affected:
up to 2.8.4
Fixed in:
2.8.5
Disclosed:
Jan 29, 2020

CVE-2020-8426 on NVD →

Elementor Page Builder < 2.8.5 - Authenticated Reflected XSS

medium
Affected:
up to 2.8.5
Fixed in:
2.8.5
Disclosed:
Jan 29, 2020

CVE-2020-8426 on NVD →

Elementor Page Builder < 2.7.7 - Authenticated Stored XSS

medium
Affected:
up to 2.7.7
Fixed in:
2.7.7
Disclosed:
Jan 29, 2020

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.7.6 (closed)

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Marc Alexandre Montpas (Sucuri) in WordPress Elementor Page Builder plugin (versions <= 2.7.5).

Affected:
up to 2.7.6
Fixed in:
2.7.6
Disclosed:
Jan 29, 2020

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.7.6 (closed)

unknown

The Elementor Website Builder for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.5 that makes it possible for attackers to inject arbitrary web scripts via the elementor_js_log AJAX action. This requires low-level authenticated user access to exploit.

Affected:
up to 2.7.6
Fixed in:
2.7.6
Disclosed:
Jan 29, 2020

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.8.5 (closed)

unknown

[en] The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.

Affected:
up to 2.8.5
Fixed in:
2.8.5
Disclosed:
Jan 28, 2020

CVE-2020-8426 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.8.4 (closed)

unknown

[en] The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jan 22, 2020

CVE-2020-7109 on NVD →

Elementor Website Builder <= 2.8.3 - Cross-Site Scripting

high

The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

CVSS:
7.2
Affected:
up to 2.8.3
Fixed in:
2.8.4
Disclosed:
Jan 19, 2020

CVE-2020-7109 on NVD →

Elementor Page Builder < 2.8.4 - Cross-Site Scripting (XSS)

medium
Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jan 19, 2020

CVE-2020-7109 on NVD →

Elementor < 2.7.5 - Authenticated Arbitrary File Upload

critical
Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Jan 14, 2020

CVE-2020-7055 on NVD →

Elementor Website Builder <= 2.7.4 - Arbitrary File Upload

high

The Elementor Website Builder plugin for WordPress is vulnerable to arbitrary file upload by subscriber level users and above due to missing authorization on the Import Templates function, which makes it possible for attackers to gain remote code execution. This affects versions up to 2.7.5.

CVSS:
8.8
Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Oct 28, 2019

CVE-2020-7055 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 1.8.0 (closed)

unknown

[en] The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Sep 10, 2019

CVE-2017-18596 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 1.8.0 (closed)

unknown

Authenticated Unrestricted Editing vulnerability found by James Golovich in WordPress Elementor Page Builder (version <=1.7.12).

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Dec 2, 2017

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 1.8.8 (closed)

unknown

Potential Privilege Escalation vulnerability found in WordPress Elementor Page Builder (versions <=1.8.7).

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Dec 2, 2017

Elementor Website Builder <= 1.7.12 - Missing Authorization

high

The Elementor Website Builder plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 1.7.12. This is due to many AJAX actions being accessible to all logged-in users due to a lack of capability checks on the associated functions. This makes it possible for authenticated attackers...

CVSS:
8.8
Affected:
up to 1.7.12
Fixed in:
1.8.0
Disclosed:
Nov 27, 2017

CVE-2017-18596 on NVD →

Elementor Page Builder < 1.8.0 - Authenticated Unrestricted Editing

unknown
Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Nov 27, 2017

CVE-2017-18596 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.8 (closed)

unknown

Jerome Bruandet, from NinTechNet, discovered a bypass in the SVG sanitizer, which could lead to an authenticated stored XSS issue from users with the upload_files capability.

Affected:
up to 2.9.8
Fixed in:
2.9.8

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.7.7 (closed)

unknown

According to the original researcher, &quot;A successful attack results in malicious scripts being injected on the plugin&rsquo;s System Info page&quot;

Affected:
up to 2.7.7
Fixed in:
2.7.7

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.13.2 (closed)

unknown

The plugin does not check user capabilities on several functions, allowing authenticated attackers with a low amount of privilege (such as Subscribers) to perform actions that should only be available to users with higher privileges.

Affected:
up to 3.13.2
Fixed in:
3.13.2

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.29.1 (closed)

unknown
Affected:
up to 3.29.1
Fixed in:
3.29.1

CVE-2024-50555 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.30.3 (closed)

unknown
Affected:
up to 3.30.3
Fixed in:
3.30.3

CVE-2025-4566 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.29.1 (closed)

unknown
Affected:
up to 3.29.1
Fixed in:
3.29.1

CVE-2025-3075 on NVD →

Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.30.3 (closed)

unknown
Affected:
up to 3.30.3
Fixed in:
3.30.3

CVE-2025-8081 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database