CVE-2025-8081
MEDIUMElementor Website Builder < 3.30.3 - Path Traversal
Title source: ruleDescription
The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Exploits (1)
Scores
CVSS v3
4.9
EPSS
0.0007
EPSS Percentile
22.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
elementor/website_builder
< 3.30.3
elemntor/Elementor Website Builder – more than just a page builder
< 3.30.2
Published
Aug 12, 2025
Tracked Since
Feb 18, 2026