Elementor Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Elementor products.
Products
- Elementor Website Builder11 vulnerabilities
- Website Builder7 vulnerabilities
- Elementor Pro3 vulnerabilities
- website_builder3 vulnerabilities
- Ally2 vulnerabilities
- elementor_pro2 vulnerabilities
- elementor1 vulnerability
- Elementor Website Builder (WordPress plugin)1 vulnerability
- elementor_page_builder1 vulnerability
- Hello Elementor1 vulnerability
- Image Optimizer by Elementor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57619MEDIUM | WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure vulnerabilityContributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. CWE-862Jun 25, 2026 | CVSS6.5v3.1 | EPSS0.262% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49782MEDIUM | WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0. CWE-862Jun 2, 2026 | CVSS5.4v3.1 | EPSS0.198% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
WordPress Elementor Website Builder plugin <= 3.35.5 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5. CWE-862Mar 13, 2026 | CVSS2.7v3.1 | EPSS0.183% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-32352MEDIUM | WordPress Elementor Website Builder plugin <= 3.35.5 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows DOM-Based XSS.This issue affects Elementor Website Builder: from n/a through <= 3.35.5. CWE-79Mar 13, 2026 | CVSS6.5v3.1 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-50555MEDIUM | WordPress Elementor Website Builder plugin <= 3.29.0 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows Stored XSS.This issue affects Elementor Website Builder: from n/a through <= 3.29.0. CWE-79Feb 20, 2026 | CVSS6.5v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25387MEDIUM | WordPress Image Optimizer by Elementor plugin <= 1.7.1 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1. CWE-862Feb 19, 2026 | CVSS4.3v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25386MEDIUM | WordPress Ally plugin <= 4.0.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Ally pojo-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ally: from n/a through <= 4.0.2. CWE-862Feb 19, 2026 | CVSS5.3v3.1 | EPSS0.214% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67588MEDIUM | WordPress Elementor Website Builder plugin <= 3.33.0 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.33.0. CWE-862Dec 9, 2025 | CVSS4.3v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32640MEDIUM | WordPress One Click Accessibility plugin <= 3.1.0 - Cross-Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Ally pojo-accessibility allows Stored XSS.This issue affects Ally: from n/a through <= 3.1.0. CWE-79Apr 9, 2025 | CVSS5.9v3.1 | EPSS0.347% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-54444MEDIUM | WordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows Stored XSS.This issue affects Elementor Website Builder: from n/a through <= 3.25.10. CWE-79Feb 25, 2025 | CVSS6.5v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35656HIGH | WordPress Elementor Pro <= 3.21.2 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected XSS.This issue affects Elementor Pro: from n/a through 3.21.2. CWE-79Jul 22, 2024 | CVSS7.1v3.1 | EPSS0.331% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37437MEDIUM | WordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.This issue affects Elementor Website Builder: from n/a through <= 3.22.1. | CVSS5.5v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35050MEDIUM | WordPress Elementor Pro plugin <= 3.13.0 - Auth. Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0. CWE-862Jun 19, 2024 | CVSS5.4v3.1 | EPSS0.314% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33922MEDIUM | WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2. CWE-862Jun 11, 2024 | CVSS4.3v3.1 | EPSS0.338% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-24934HIGH | WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0. CWE-22May 17, 2024 | CVSS8.5v3.1 | EPSS0.715% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47504MEDIUM | WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerabilityImproper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4. CWE-287Apr 24, 2024 | CVSS6.5v3.1 | EPSS1.45% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32681MEDIUM | WordPress Prime Slider plugin <= 3.13.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2. CWE-862Apr 22, 2024 | CVSS4.3v3.1 | EPSS0.399% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-31289MEDIUM | WordPress Hello Elementor theme <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Elementor Hello Elementor.This issue affects Hello Elementor: from n/a through 3.0.0. CWE-352Apr 12, 2024 | CVSS4.3v3.1 | EPSS0.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2781MEDIUM | Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tagThe Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_html_tag attribute in all versions up to, and including, 3.20.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Mar 27, 2024 | CVSS6.4v3.1 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-48777CRITICAL | WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1. | CVSS9.9v3.1 | EPSS4.1% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-23523MEDIUM | WordPress Elementor Pro plugin <= 3.19.2 - Contributor+ Arbitrary User Meta Data Retrieval vulnerabilityExposure of Sensitive Information to an Unauthorized Actor vulnerability in Elementor Pro.This issue affects Elementor Pro: from n/a through 3.19.2. CWE-200Mar 16, 2024 | CVSS6.5v3.1 | EPSS0.529% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3124HIGH | Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_optionThe Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation. CWE-862Jun 7, 2023 | CVSS8.8v3.1 | EPSS22.7% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29455MEDIUM | WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerabilityDOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions. | CVSS4.7v3.1 | EPSS23.2% | PoCs6 | SignalsNot listed in CISA KEVNo known ransomware use2 Nuclei templates | STIX |
CVE-2022-1329HIGH | Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code ExecutionThe Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2. | CVSS8.8v3.1 | EPSS92.7% | PoCs6 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-24205MEDIUM | Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box WidgetIn the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed… CWE-79Apr 5, 2021 | CVSS5.4v3.1 | EPSS0.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |