Elementor Vulnerabilities and Affected Products
Vulnerabilities associated with website_builder.
Products
Clear product- Elementor Website Builder11 vulnerabilities
- Website Builder7 vulnerabilities
- Elementor Pro3 vulnerabilities
- website_builder3 vulnerabilities
- Ally2 vulnerabilities
- elementor_pro2 vulnerabilities
- elementor1 vulnerability
- Elementor Website Builder (WordPress plugin)1 vulnerability
- elementor_page_builder1 vulnerability
- Hello Elementor1 vulnerability
- Image Optimizer by Elementor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-24934HIGH | WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0. CWE-22May 17, 2024 | CVSS8.5v3.1 | EPSS0.715% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2781MEDIUM | Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tagThe Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_html_tag attribute in all versions up to, and including, 3.20.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Mar 27, 2024 | CVSS6.4v3.1 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-48777CRITICAL | WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1. | CVSS9.9v3.1 | EPSS4.1% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |