Elementor Vulnerabilities and Affected Products
Vulnerabilities associated with Elementor Website Builder.
Products
Clear product- Elementor Website Builder11 vulnerabilities
- Website Builder7 vulnerabilities
- Elementor Pro3 vulnerabilities
- website_builder3 vulnerabilities
- Ally2 vulnerabilities
- elementor_pro2 vulnerabilities
- elementor1 vulnerability
- Elementor Website Builder (WordPress plugin)1 vulnerability
- elementor_page_builder1 vulnerability
- Hello Elementor1 vulnerability
- Image Optimizer by Elementor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57619MEDIUM | WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure vulnerabilityContributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. CWE-862Jun 25, 2026 | CVSS6.5v3.1 | EPSS0.262% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49782MEDIUM | WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0. CWE-862Jun 2, 2026 | CVSS5.4v3.1 | EPSS0.198% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
WordPress Elementor Website Builder plugin <= 3.35.5 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5. CWE-862Mar 13, 2026 | CVSS2.7v3.1 | EPSS0.183% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-32352MEDIUM | WordPress Elementor Website Builder plugin <= 3.35.5 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows DOM-Based XSS.This issue affects Elementor Website Builder: from n/a through <= 3.35.5. CWE-79Mar 13, 2026 | CVSS6.5v3.1 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-50555MEDIUM | WordPress Elementor Website Builder plugin <= 3.29.0 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows Stored XSS.This issue affects Elementor Website Builder: from n/a through <= 3.29.0. CWE-79Feb 20, 2026 | CVSS6.5v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67588MEDIUM | WordPress Elementor Website Builder plugin <= 3.33.0 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.33.0. CWE-862Dec 9, 2025 | CVSS4.3v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-54444MEDIUM | WordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows Stored XSS.This issue affects Elementor Website Builder: from n/a through <= 3.25.10. CWE-79Feb 25, 2025 | CVSS6.5v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37437MEDIUM | WordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.This issue affects Elementor Website Builder: from n/a through <= 3.22.1. | CVSS5.5v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33922MEDIUM | WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2. CWE-862Jun 11, 2024 | CVSS4.3v3.1 | EPSS0.338% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-24934HIGH | WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0. CWE-22May 17, 2024 | CVSS8.5v3.1 | EPSS0.715% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47504MEDIUM | WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerabilityImproper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4. CWE-287Apr 24, 2024 | CVSS6.5v3.1 | EPSS1.45% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |