Elementor <= 4.1.3 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Jun 29, 2026
CVE-2026-8825 on NVD →
Elementor Website Builder – more than just a page builder <= 4.1.3 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Jun 25, 2026
CVE-2026-57619 on NVD →
Elementor Website Builder – more than just a page builder <= 4.1.0 - Missing Authorization
medium
The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unau...
- CVSS:
- 4.3
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.1
- Disclosed:
- Jun 2, 2026
CVE-2026-49782 on NVD →
Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API
medium
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0.4. This is due to insufficient input sanitization when processing form-encoded REST API requests. The plugin registers the _elementor_data meta field w...
- CVSS:
- 6.4
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Apr 30, 2026
CVE-2026-6127 on NVD →
Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API
medium
The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 3.35.5
- Fixed in:
- 3.35.6
- Disclosed:
- Apr 7, 2026
CVE-2025-14732 on NVD →
Elementor Website Builder - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
medium
Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
- CVSS:
- 4.3
- Affected:
- up to 3.35.7
- Fixed in:
- 3.35.8
- Disclosed:
- Mar 30, 2026
Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template
medium
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats non-published templates as readable without...
- CVSS:
- 4.3
- Affected:
- up to 3.35.7
- Fixed in:
- 3.35.8
- Disclosed:
- Mar 25, 2026
CVE-2026-1206 on NVD →
Elementor Website Builder < 3.35.8 - Contributor+ Sensitive Information Exposure via Elementor Template
medium
- Affected:
- up to 3.35.8
- Fixed in:
- 3.35.8
- Disclosed:
- Mar 25, 2026
CVE-2026-1206 on NVD →
Elementor Website Builder <= 3.35.5 - Missing Authorization
medium
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.35.5. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.35.5
- Fixed in:
- 3.35.6
- Disclosed:
- Mar 7, 2026
CVE-2026-32445 on NVD →
Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...
- CVSS:
- 6.4
- Affected:
- up to 3.35.5
- Fixed in:
- 3.35.6
- Disclosed:
- Feb 13, 2026
CVE-2026-32352 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.33.4
unknown
[en] The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possible for authenticated attackers, w...
- Affected:
- up to 3.33.4
- Fixed in:
- 3.33.4
- Disclosed:
- Dec 16, 2025
CVE-2025-11220 on NVD →
Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path
medium
The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possible for authenticated attackers, with c...
- CVSS:
- 6.4
- Affected:
- up to 3.33.3
- Fixed in:
- 3.33.4
- Disclosed:
- Dec 15, 2025
CVE-2025-11220 on NVD →
Elementor < 3.33.4 - Contributor+ Stored DOM-Based XSS via Text Path
medium
- Affected:
- up to 3.33.4
- Fixed in:
- 3.33.4
- Disclosed:
- Dec 15, 2025
CVE-2025-11220 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] <= 3.33.0 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.33.0.
- Affected:
- up to 3.33.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67588 on NVD →
Elementor Website Builder <= 3.33.0 - Missing Authorization
medium
The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.33.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an...
- CVSS:
- 4.3
- Affected:
- up to 3.33.0
- Fixed in:
- 3.33.1
- Disclosed:
- Nov 25, 2025
CVE-2025-67588 on NVD →
Elementor Website Builder < 3.33.1 - Missing Authorization
medium
- Affected:
- up to 3.33.1
- Fixed in:
- 3.33.1
- Disclosed:
- Nov 25, 2025
CVE-2025-67588 on NVD →
Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import
medium
The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the...
- CVSS:
- 4.9
- Affected:
- up to 3.30.2
- Fixed in:
- 3.30.3
- Disclosed:
- Aug 11, 2025
CVE-2025-8081 on NVD →
Elementor < 3.30.3 - Admin+ Arbitrary File Read via Image Import
medium
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
- Disclosed:
- Aug 11, 2025
CVE-2025-8081 on NVD →
Elementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...
- CVSS:
- 6.4
- Affected:
- up to 3.29.0
- Fixed in:
- 3.29.1
- Disclosed:
- Jul 28, 2025
CVE-2025-3075 on NVD →
Elementor <= 3.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget
medium
The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 3.30.2
- Fixed in:
- 3.30.3
- Disclosed:
- Jul 28, 2025
CVE-2025-4566 on NVD →
Elementor < 3.29.1 - Contributor+ Stored XSS
medium
- Affected:
- up to 3.29.1
- Fixed in:
- 3.29.1
- Disclosed:
- Jul 28, 2025
CVE-2025-3075 on NVD →
Elementor < 3.30.3 - Contributor+ Stored XSS via Text Path Widget
medium
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
- Disclosed:
- Jul 28, 2025
CVE-2025-4566 on NVD →
Elementor Website Builder <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...
- CVSS:
- 6.4
- Affected:
- up to 3.29.0
- Fixed in:
- 3.29.1
- Disclosed:
- Jun 19, 2025
CVE-2024-50555 on NVD →
Elementor Website Builder < 3.29.1 - Contributor+ Stored XSS
medium
- Affected:
- up to 3.29.1
- Fixed in:
- 3.29.1
- Disclosed:
- Jun 19, 2025
CVE-2024-50555 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.25.11 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder allows Stored XSS. This issue affects Elementor Website Builder: from n/a through 3.25.10.
- Affected:
- up to 3.25.11
- Fixed in:
- 3.25.11
- Disclosed:
- Feb 25, 2025
CVE-2024-54444 on NVD →
Elementor Website Builder <= 3.25.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.25.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 3.25.10
- Fixed in:
- 3.25.11
- Disclosed:
- Feb 24, 2025
CVE-2024-54444 on NVD →
Elementor Website Builder < 3.25.11 - Contributor+ Stored XSS
medium
- Affected:
- up to 3.25.11
- Fixed in:
- 3.25.11
- Disclosed:
- Feb 24, 2025
CVE-2024-54444 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.27.5 (closed)
unknown
[en] The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- Affected:
- up to 3.27.5
- Fixed in:
- 3.27.5
- Disclosed:
- Feb 20, 2025
CVE-2024-13445 on NVD →
Elementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 3.27.4
- Fixed in:
- 3.27.5
- Disclosed:
- Feb 19, 2025
CVE-2024-13445 on NVD →
Elementor Website Builder < 3.27.5 - Contributor+ Stored XSS
medium
- Affected:
- up to 3.27.5
- Fixed in:
- 3.27.5
- Disclosed:
- Feb 19, 2025
CVE-2024-13445 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.25.10 (closed)
unknown
[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...
- Affected:
- up to 3.25.10
- Fixed in:
- 3.25.10
- Disclosed:
- Dec 21, 2024
CVE-2024-10453 on NVD →
Elementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings
medium
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible...
- CVSS:
- 6.4
- Affected:
- up to 3.25.9
- Fixed in:
- 3.25.10
- Disclosed:
- Dec 20, 2024
CVE-2024-10453 on NVD →
Elementor Website Builder < 3.25.10 - Contributor+ Stored XSS via Typography Settings
medium
- Affected:
- up to 3.25.10
- Fixed in:
- 3.25.10
- Disclosed:
- Dec 20, 2024
CVE-2024-10453 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.25.8 (closed)
unknown
[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...
- Affected:
- up to 3.25.8
- Fixed in:
- 3.25.8
- Disclosed:
- Nov 26, 2024
CVE-2024-8236 on NVD →
Elementor Website Builder – More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 3.25.7
- Fixed in:
- 3.25.8
- Disclosed:
- Nov 25, 2024
CVE-2024-8236 on NVD →
Elementor Website Builder < 3.25.8 - Contributor+ Stored XSS
medium
- Affected:
- up to 3.25.8
- Fixed in:
- 3.25.8
- Disclosed:
- Nov 25, 2024
CVE-2024-8236 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.24.6 (closed)
unknown
[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either...
- Affected:
- up to 3.24.6
- Fixed in:
- 3.24.6
- Disclosed:
- Oct 15, 2024
CVE-2024-6757 on NVD →
Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function
medium
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excer...
- CVSS:
- 4.3
- Affected:
- up to 3.24.5
- Fixed in:
- 3.24.6
- Disclosed:
- Oct 14, 2024
CVE-2024-6757 on NVD →
Elementor < 3.24.6 - Contributor+ Information Exposure via get_image_alt
medium
- Affected:
- up to 3.24.6
- Fixed in:
- 3.24.6
- Disclosed:
- Oct 14, 2024
CVE-2024-6757 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.24.0 (closed)
unknown
[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...
- Affected:
- up to 3.24.0
- Fixed in:
- 3.24.0
- Disclosed:
- Sep 11, 2024
CVE-2024-5416 on NVD →
Elementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets
medium
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...
- CVSS:
- 5.4
- Affected:
- up to 3.23.4
- Fixed in:
- 3.24.0
- Disclosed:
- Sep 10, 2024
CVE-2024-5416 on NVD →
Elementor Website Builder – More than Just a Page Builder < 3.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets
medium
- Affected:
- up to 3.24.0
- Fixed in:
- 3.24.0
- Disclosed:
- Sep 10, 2024
CVE-2024-5416 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.22.2 (closed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Cross-Site Scripting (XSS), Stored XSS.This issue affects Elementor Website Builder: from n/a through 3.22.1.
- Affected:
- up to 3.22.2
- Fixed in:
- 3.22.2
- Disclosed:
- Jul 9, 2024
CVE-2024-37437 on NVD →
Elementor Website Builder <= 3.22.1 - Authenticated (Contributor+) Arbitrary SVG Download
medium
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary SVG file download in all versions up to, and including, 3.22.1. This is due to the plugin not properly restricting access to files. This makes it possible for authenticated attackers, with contributor-level acc...
- CVSS:
- 6.4
- Affected:
- up to 3.22.1
- Fixed in:
- 3.22.2
- Disclosed:
- Jun 28, 2024
CVE-2024-37437 on NVD →
Elementor Website Builder < 3.22.2 - Contributor+ Arbitrary SVG Download
unknown
- Affected:
- up to 3.22.2
- Fixed in:
- 3.22.2
- Disclosed:
- Jun 28, 2024
CVE-2024-37437 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.13.3 (closed)
unknown
[en] Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.
- Affected:
- up to 3.13.3
- Fixed in:
- 3.13.3
- Disclosed:
- Jun 11, 2024
CVE-2023-33922 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.22.0-beta2 (closed)
unknown
[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- Affected:
- up to 3.22.0-beta2
- Fixed in:
- 3.22.0-beta2
- Disclosed:
- May 21, 2024
CVE-2024-4619 on NVD →
Elementor Website Builder – More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 3.21.5
- Fixed in:
- 3.21.6
- Disclosed:
- May 20, 2024
CVE-2024-4619 on NVD →
Elementor Website Builder < 3.21.6 - Contributor+ DOM Stored XSS
medium
- Affected:
- up to 3.21.6
- Fixed in:
- 3.21.6
- Disclosed:
- May 20, 2024
CVE-2024-4619 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.19.1 (closed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.
- Affected:
- up to 3.19.1
- Fixed in:
- 3.19.1
- Disclosed:
- May 17, 2024
CVE-2024-24934 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.16.5 (closed)
unknown
[en] Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.
- Affected:
- up to 3.16.5
- Fixed in:
- 3.16.5
- Disclosed:
- Apr 24, 2024
CVE-2023-47504 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.20.3 (closed)
unknown
[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attacke...
- Affected:
- up to 3.20.3
- Fixed in:
- 3.20.3
- Disclosed:
- Apr 9, 2024
CVE-2024-2117 on NVD →
Elementor Website Builder – More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget
medium
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attackers wi...
- CVSS:
- 6.4
- Affected:
- up to 3.20.2
- Fixed in:
- 3.20.3
- Disclosed:
- Mar 26, 2024
CVE-2024-2117 on NVD →
Elementor Website Builder < 3.20.3 - Contributor+ DOM Stored XSS
medium
- Affected:
- up to 3.20.3
- Fixed in:
- 3.20.3
- Disclosed:
- Mar 26, 2024
CVE-2024-2117 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.18.2 (closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.
- Affected:
- up to 3.18.2
- Fixed in:
- 3.18.2
- Disclosed:
- Mar 26, 2024
CVE-2023-48777 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.19.0 (closed)
unknown
[en] The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it po...
- Affected:
- up to 3.19.0
- Fixed in:
- 3.19.0
- Disclosed:
- Feb 20, 2024
CVE-2024-0506 on NVD →
Elementor <= 3.19.0 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization
high
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary file deletions and PHAR deserialization in version up to, and including 3.19.0. This is due to the plugin not providing sufficient path validation on the 'tmp_name' parameter . This makes it possible for authen...
- CVSS:
- 8.8
- Affected:
- up to 3.19.0
- Fixed in:
- 3.19.1
- Disclosed:
- Feb 7, 2024
CVE-2024-24934 on NVD →
Elementor Website Builder – More than Just a Page Builder <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt
medium
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possibl...
- CVSS:
- 6.4
- Affected:
- up to 3.18.3
- Fixed in:
- 3.19.0
- Disclosed:
- Feb 7, 2024
CVE-2024-0506 on NVD →
Elementor < 3.19.1 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization
critical
- Affected:
- up to 3.19.1
- Fixed in:
- 3.19.1
- Disclosed:
- Feb 7, 2024
CVE-2024-24934 on NVD →
Elementor Website Builder – More than Just a Page Builder < 3.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt
medium
- Affected:
- up to 3.19.0
- Fixed in:
- 3.19.0
- Disclosed:
- Feb 7, 2024
CVE-2024-0506 on NVD →
Elementor <= 3.18.1 - Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import
high
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Remote Code Execution via file upload in all versions up to and including 3.18.1 via the template import functionality. This makes it possible for authenticated attackers, with contributor-level access and above, to uplo...
- CVSS:
- 8.8
- Affected:
- up to 3.18.1
- Fixed in:
- 3.18.2
- Disclosed:
- Dec 6, 2023
CVE-2023-48777 on NVD →
Elementor < 3.18.2 - Contributor+ Arbitrary File Upload to RCE via Template Import
critical
- Affected:
- up to 3.18.2
- Fixed in:
- 3.18.2
- Disclosed:
- Dec 6, 2023
CVE-2023-48777 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.16.5 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4.
- Affected:
- up to 3.16.5
- Fixed in:
- 3.16.5
- Disclosed:
- Nov 30, 2023
CVE-2023-47505 on NVD →
Elementor Website Builder <= 3.16.4 - Missing Authorization to Arbitrary Attachment Read
medium
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_inline_svg function in all versions up to, and including, 3.16.4. This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary at...
- CVSS:
- 6.5
- Affected:
- up to 3.16.4
- Fixed in:
- 3.16.5
- Disclosed:
- Nov 8, 2023
CVE-2023-47504 on NVD →
Elementor Website Builder <= 3.16.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()
medium
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the get_inline_svg() function in versions up to, and including, 3.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abo...
- CVSS:
- 6.4
- Affected:
- up to 3.16.4
- Fixed in:
- 3.16.5
- Disclosed:
- Nov 8, 2023
CVE-2023-47505 on NVD →
Elementor Website Builder < 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()
medium
- Affected:
- up to 3.16.5
- Fixed in:
- 3.16.5
- Disclosed:
- Nov 8, 2023
CVE-2023-47505 on NVD →
Elementor Website Builder < 3.16.5 - Missing Authorization to Arbitrary Attachment Read
medium
- Affected:
- up to 3.16.5
- Fixed in:
- 3.16.5
- Disclosed:
- Nov 8, 2023
CVE-2023-47504 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.5.5 (closed)
unknown
[en] The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
- Affected:
- up to 3.5.5
- Fixed in:
- 3.5.5
- Disclosed:
- Aug 14, 2023
CVE-2022-4953 on NVD →
Elementor <= 3.5.4 - DOM-Based iFrame Injection
medium
The Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘settings’ hash parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary iframes in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.5
- Disclosed:
- Jul 19, 2023
CVE-2022-4953 on NVD →
Elementor < 3.5.5 - Iframe Injection
unknown
- Affected:
- up to 3.5.5
- Fixed in:
- 3.5.5
- Disclosed:
- Jul 19, 2023
CVE-2022-4953 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.8 (closed)
unknown
[en] The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user...
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.8
- Disclosed:
- Jun 7, 2023
CVE-2020-36703 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.12.2 (closed)
unknown
[en] The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.2
- Disclosed:
- May 30, 2023
CVE-2023-0329 on NVD →
Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item
medium
The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template "save_item" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or above, to create templates with an arbitra...
- CVSS:
- 5.4
- Affected:
- up to 3.13.3
- Fixed in:
- 3.13.3
- Disclosed:
- May 22, 2023
CVE-2023-33922 on NVD →
Elementor <= 3.13.1 - Missing Authorization to Settings Update
medium
The Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the register_as_beta_tester(), ajax_enable_safe_mode(), ajax_get_category_items(), and ajax_re_migrate_globals() functions called via AJAX actions in versions up to, and including, 3.13.1. This make...
- CVSS:
- 5.4
- Affected:
- up to 3.13.1
- Fixed in:
- 3.13.2
- Disclosed:
- May 12, 2023
Elementor Website Builder < 3.13.2 - Missing Authorization
medium
- Affected:
- up to 3.13.2
- Fixed in:
- 3.13.2
- Disclosed:
- May 12, 2023
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.13.2 (closed)
unknown
The Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the register_as_beta_tester(), ajax_enable_safe_mode(), ajax_get_category_items(), and ajax_re_migrate_globals() functions called via AJAX actions in versions up to, and including, 3.13.1. This make...
- Affected:
- up to 3.13.2
- Fixed in:
- 3.13.2
- Disclosed:
- May 12, 2023
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.13.2 (closed)
unknown
Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.13.2).
An unknown person discovered and reported this Broken Access Control vulnerability in WordPress Elementor Website Builder Plugin. This vulnerability has been fixed in version 3.13.2.
- Affected:
- up to 3.13.2
- Fixed in:
- 3.13.2
- Disclosed:
- May 12, 2023
Elementor Website Builder < 3.12.2 - Admin+ SQLi
unknown
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.2
- Disclosed:
- May 2, 2023
CVE-2023-0329 on NVD →
Elementor <= 3.12.1 - Authenticated(Administrator+) SQL Injection via 'replace_urls'
medium
The Elementor plugin for WordPress is vulnerable to blind SQL Injection via the 'replace_urls' functionality in versions up to, and including, 3.12.1 due to insufficient escaping on the user supplied 'old' and 'new' parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for aut...
- CVSS:
- 6.6
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.2
- Disclosed:
- Apr 24, 2023
CVE-2023-0329 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.12.2 (closed)
unknown
The Elementor plugin for WordPress is vulnerable to blind SQL Injection via the 'replace_urls' functionality in versions up to, and including, 3.12.1 due to insufficient escaping on the user supplied 'old' and 'new' parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for aut...
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.2
- Disclosed:
- Apr 24, 2023
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.12.2 (closed)
unknown
Update the Elementor plugin to the latest available version (at least 3.12.2).
An unknown person discovered and reported this SQL Injection vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing infor...
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.2
- Disclosed:
- Apr 24, 2023
Elementor Website Builder <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting
medium
The Elementor Website Builder plugin for WordPress is vulnerable to Unauthenticated DOM-based Reflected Cross-Site Scripting via the ‘videoType’ and 'onError' parameter in the lightbox module in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for u...
- CVSS:
- 6.1
- Affected:
- up to 3.5.5
- Fixed in:
- 3.5.6
- Disclosed:
- Jun 13, 2022
CVE-2022-29455 on NVD →
Elementor < 3.5.6 - DOM Reflected Cross-Site Scripting
medium
- Affected:
- up to 3.5.6
- Fixed in:
- 3.5.6
- Disclosed:
- Jun 13, 2022
CVE-2022-29455 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.5.6 (closed)
unknown
[en] DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
- Affected:
- up to 3.5.6
- Fixed in:
- 3.5.6
- Disclosed:
- Jun 13, 2022
CVE-2022-29455 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] >= 3.6.0 - <= 3.6.2 (closed)
unknown
[en] The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used...
- Affected:
- 3.6.0 – 3.6.2
- Fixed in:
- 3.6.2
- Disclosed:
- Apr 19, 2022
CVE-2022-1329 on NVD →
Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution
high
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to o...
- CVSS:
- 8.8
- Affected:
- 3.6.0 – 3.6.2
- Fixed in:
- 3.6.3
- Disclosed:
- Apr 13, 2022
CVE-2022-1329 on NVD →
Elementor 3.6.0-3.6.2 - Subscriber+ Arbitrary File Upload
critical
- Affected:
- 3.6.0 – 3.6.3
- Fixed in:
- 3.6.3
- Disclosed:
- Apr 13, 2022
CVE-2022-1329 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.6.3 (closed)
unknown
[en] The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.3
- Disclosed:
- Nov 23, 2021
CVE-2021-24891 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4 (closed)
unknown
[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Apr 5, 2021
CVE-2021-24202 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4 (closed)
unknown
[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Apr 5, 2021
CVE-2021-24203 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4 (closed)
unknown
[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Apr 5, 2021
CVE-2021-24204 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4 (closed)
unknown
[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builde...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Apr 5, 2021
CVE-2021-24205 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4 (closed)
unknown
[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_buil...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Apr 5, 2021
CVE-2021-24206 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4 (closed)
unknown
[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Apr 5, 2021
CVE-2021-24201 on NVD →
Elementor < 3.4.8 - DOM Cross-Site-Scripting
unknown
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.8
- Disclosed:
- Mar 24, 2021
CVE-2021-24891 on NVD →
Elementor Website Builder <= 3.4.7 - DOM-based Cross-Site Scripting
medium
The Elementor Website Builder plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the '#elementor-action:action=lightbox&settings=' DOM in versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...
- CVSS:
- 6.1
- Affected:
- 0.1.0 – 3.4.7
- Fixed in:
- 3.4.8
- Disclosed:
- Mar 23, 2021
CVE-2021-24891 on NVD →
Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_html_tag
medium
In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_build...
- CVSS:
- 6.4
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24204 on NVD →
Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_size
medium
In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’...
- CVSS:
- 6.4
- Affected:
- 0.1.0 – 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24206 on NVD →
Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag
medium
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ reque...
- CVSS:
- 6.4
- Affected:
- 0.1.0 – 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24201 on NVD →
Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_size Parameter
medium
In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ re...
- CVSS:
- 6.4
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24205 on NVD →
Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via header_size
medium
In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ req...
- CVSS:
- 6.4
- Affected:
- 0.1.0 – 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24202 on NVD →
Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag
medium
In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ reque...
- CVSS:
- 6.4
- Affected:
- 0.1.0 – 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24203 on NVD →
Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element
medium
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24201 on NVD →
Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget
medium
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24202 on NVD →
Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget
medium
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24203 on NVD →
Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget
medium
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24204 on NVD →
Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget
medium
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24205 on NVD →
Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget
medium
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
CVE-2021-24206 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4 (closed)
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities found by WordFence in WordPress Elementor Website Builder plugin (versions <= 3.1.1).
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Mar 17, 2021
Elementor < 3.0.14 - SVG Upload Allowed by Default
unknown
- Affected:
- up to 3.0.14
- Fixed in:
- 3.0.14
- Disclosed:
- Jan 6, 2021
CVE-2020-36171 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.0.14 (closed)
unknown
[en] The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
- Affected:
- up to 3.0.14
- Fixed in:
- 3.0.14
- Disclosed:
- Jan 6, 2021
CVE-2020-36171 on NVD →
Elementor Website Builder <= 3.0.13 - Unrestricted SVG Uploads
medium
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized malicious SVG file uploads in versions up to, and including, 3.0.13. This is due to improper restrictions on allowing SVG file uploads. This makes it possible for authenticated attackers with post editor access to upload SVG files that cou...
- CVSS:
- 6.4
- Affected:
- up to 3.0.13
- Fixed in:
- 3.0.14
- Disclosed:
- Nov 25, 2020
CVE-2020-36171 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.3 (closed)
unknown
[en] A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.3
- Disclosed:
- Sep 16, 2020
CVE-2020-20406 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.14 (closed)
unknown
[en] An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
- Affected:
- up to 2.9.14
- Fixed in:
- 2.9.14
- Disclosed:
- Aug 31, 2020
CVE-2020-15020 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.6 (closed)
unknown
[en] Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
- Affected:
- up to 2.9.6
- Fixed in:
- 2.9.6
- Disclosed:
- Aug 21, 2020
CVE-2020-20634 on NVD →
Elementor < 2.9.14 - Authenticated Stored Cross-Site Scripting
medium
- Affected:
- up to 2.9.14
- Fixed in:
- 2.9.14
- Disclosed:
- Jul 21, 2020
CVE-2020-15020 on NVD →
Elementor Website Builder <= 2.9.13 - Authenticated Stored Cross-Site Scripting
medium
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
- CVSS:
- 6.4
- Affected:
- up to 2.9.14
- Fixed in:
- 2.9.14
- Disclosed:
- Jul 7, 2020
CVE-2020-15020 on NVD →
Elementor Website Builder <= 2.9.8 - Stored Cross-Site Scripting
medium
The Elementor Website Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
- CVSS:
- 5.4
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.9
- Disclosed:
- Jun 5, 2020
CVE-2020-13864 on NVD →
Elementor Website Builder <= 2.9.8 - Stored Cross-Site Scripting
medium
The Elementor Website Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
- CVSS:
- 5.4
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.9
- Disclosed:
- Jun 5, 2020
CVE-2020-13865 on NVD →
Elementor Page Builder < 2.9.10 - Authenticated Stored XSS
medium
- Affected:
- up to 2.9.10
- Fixed in:
- 2.9.10
- Disclosed:
- Jun 5, 2020
CVE-2020-13864 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.9 (closed)
unknown
[en] The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
- Affected:
- up to 2.9.9
- Fixed in:
- 2.9.9
- Disclosed:
- Jun 5, 2020
CVE-2020-13864 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.10 (closed)
unknown
[en] The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
- Affected:
- up to 2.9.10
- Fixed in:
- 2.9.10
- Disclosed:
- Jun 5, 2020
CVE-2020-13865 on NVD →
Elementor < 2.9.8 - SVG Sanitizer Bypass leading to Authenticated Stored XSS
medium
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.8
- Disclosed:
- May 6, 2020
CVE-2020-36703 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.7.5 (closed)
unknown
[en] An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Apr 22, 2020
CVE-2020-7055 on NVD →
Elementor Website Builder <= 2.9.7 - Authenticated Stored Cross-Site Scripting
medium
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user acce...
- CVSS:
- 6.4
- Affected:
- up to 2.9.7
- Fixed in:
- 2.9.8
- Disclosed:
- Apr 21, 2020
CVE-2020-36703 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.8 (closed)
unknown
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user acce...
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.8
- Disclosed:
- Apr 21, 2020
Elementor Website Builder <= 2.9.5 - Authorization Bypass
medium
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
- CVSS:
- 6.5
- Affected:
- up to 2.9.5
- Fixed in:
- 2.9.6
- Disclosed:
- Mar 31, 2020
CVE-2020-20634 on NVD →
Elementor Page Builder < 2.9.6 - Authenticated Safe Mode Privilege Escalation
critical
- Affected:
- up to 2.9.6
- Fixed in:
- 2.9.6
- Disclosed:
- Mar 31, 2020
CVE-2020-20634 on NVD →
Elementor Website Builder <= 2.9.2 - Stored Cross-Site Scripting
medium
A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.
- CVSS:
- 6.4
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.3
- Disclosed:
- Feb 26, 2020
CVE-2020-20406 on NVD →
Elementor Website Builder <= 2.7.5 - Stored Cross-Site Scripting
medium
The Elementor Website Builder for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.5 that makes it possible for attackers to inject arbitrary web scripts via the elementor_js_log AJAX action. This requires low-level authenticated user access to exploit.
- CVSS:
- 6.4
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.6
- Disclosed:
- Jan 29, 2020
Elementor Website Builder <= 2.8.4 - Reflected Cross-Site Scripting
medium
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
- CVSS:
- 6.1
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.5
- Disclosed:
- Jan 29, 2020
CVE-2020-8426 on NVD →
Elementor Page Builder < 2.8.5 - Authenticated Reflected XSS
medium
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.5
- Disclosed:
- Jan 29, 2020
CVE-2020-8426 on NVD →
Elementor Page Builder < 2.7.7 - Authenticated Stored XSS
medium
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.7
- Disclosed:
- Jan 29, 2020
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.7.6 (closed)
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Marc Alexandre Montpas (Sucuri) in WordPress Elementor Page Builder plugin (versions <= 2.7.5).
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.6
- Disclosed:
- Jan 29, 2020
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.7.6 (closed)
unknown
The Elementor Website Builder for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.5 that makes it possible for attackers to inject arbitrary web scripts via the elementor_js_log AJAX action. This requires low-level authenticated user access to exploit.
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.6
- Disclosed:
- Jan 29, 2020
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.8.5 (closed)
unknown
[en] The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.5
- Disclosed:
- Jan 28, 2020
CVE-2020-8426 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.8.4 (closed)
unknown
[en] The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- Jan 22, 2020
CVE-2020-7109 on NVD →
Elementor Website Builder <= 2.8.3 - Cross-Site Scripting
high
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
- CVSS:
- 7.2
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.4
- Disclosed:
- Jan 19, 2020
CVE-2020-7109 on NVD →
Elementor Page Builder < 2.8.4 - Cross-Site Scripting (XSS)
medium
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- Jan 19, 2020
CVE-2020-7109 on NVD →
Elementor < 2.7.5 - Authenticated Arbitrary File Upload
critical
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Jan 14, 2020
CVE-2020-7055 on NVD →
Elementor Website Builder <= 2.7.4 - Arbitrary File Upload
high
The Elementor Website Builder plugin for WordPress is vulnerable to arbitrary file upload by subscriber level users and above due to missing authorization on the Import Templates function, which makes it possible for attackers to gain remote code execution. This affects versions up to 2.7.5.
- CVSS:
- 8.8
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Oct 28, 2019
CVE-2020-7055 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 1.8.0 (closed)
unknown
[en] The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Sep 10, 2019
CVE-2017-18596 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 1.8.0 (closed)
unknown
Authenticated Unrestricted Editing vulnerability found by James Golovich in WordPress Elementor Page Builder (version <=1.7.12).
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Dec 2, 2017
Elementor Website Builder – More Than Just a Page Builder [elementor] < 1.8.8 (closed)
unknown
Potential Privilege Escalation vulnerability found in WordPress Elementor Page Builder (versions <=1.8.7).
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Dec 2, 2017
Elementor Website Builder <= 1.7.12 - Missing Authorization
high
The Elementor Website Builder plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 1.7.12. This is due to many AJAX actions being accessible to all logged-in users due to a lack of capability checks on the associated functions. This makes it possible for authenticated attackers...
- CVSS:
- 8.8
- Affected:
- up to 1.7.12
- Fixed in:
- 1.8.0
- Disclosed:
- Nov 27, 2017
CVE-2017-18596 on NVD →
Elementor Page Builder < 1.8.0 - Authenticated Unrestricted Editing
unknown
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Nov 27, 2017
CVE-2017-18596 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.8 (closed)
unknown
Jerome Bruandet, from NinTechNet, discovered a bypass in the SVG sanitizer, which could lead to an authenticated stored XSS issue from users with the upload_files capability.
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.8
Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.7.7 (closed)
unknown
According to the original researcher, "A successful attack results in malicious scripts being injected on the plugin’s System Info page"
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.7
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.13.2 (closed)
unknown
The plugin does not check user capabilities on several functions, allowing authenticated attackers with a low amount of privilege (such as Subscribers) to perform actions that should only be available to users with higher privileges.
- Affected:
- up to 3.13.2
- Fixed in:
- 3.13.2
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.29.1 (closed)
unknown
- Affected:
- up to 3.29.1
- Fixed in:
- 3.29.1
CVE-2024-50555 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.30.3 (closed)
unknown
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
CVE-2025-4566 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.29.1 (closed)
unknown
- Affected:
- up to 3.29.1
- Fixed in:
- 3.29.1
CVE-2025-3075 on NVD →
Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.30.3 (closed)
unknown
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
CVE-2025-8081 on NVD →