Elementor Vulnerabilities and Affected Products
Vulnerabilities associated with Elementor Pro.
Products
Clear product- Elementor Website Builder11 vulnerabilities
- Website Builder7 vulnerabilities
- Elementor Pro3 vulnerabilities
- website_builder3 vulnerabilities
- Ally2 vulnerabilities
- elementor_pro2 vulnerabilities
- elementor1 vulnerability
- Elementor Website Builder (WordPress plugin)1 vulnerability
- elementor_page_builder1 vulnerability
- Hello Elementor1 vulnerability
- Image Optimizer by Elementor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-35656HIGH | WordPress Elementor Pro <= 3.21.2 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected XSS.This issue affects Elementor Pro: from n/a through 3.21.2. CWE-79Jul 22, 2024 | CVSS7.1v3.1 | EPSS0.331% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35050MEDIUM | WordPress Elementor Pro plugin <= 3.13.0 - Auth. Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0. CWE-862Jun 19, 2024 | CVSS5.4v3.1 | EPSS0.314% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23523MEDIUM | WordPress Elementor Pro plugin <= 3.19.2 - Contributor+ Arbitrary User Meta Data Retrieval vulnerabilityExposure of Sensitive Information to an Unauthorized Actor vulnerability in Elementor Pro.This issue affects Elementor Pro: from n/a through 3.19.2. CWE-200Mar 16, 2024 | CVSS6.5v3.1 | EPSS0.529% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |