VendorsElementorelementor_page_builderany version
Vulnerabilities

Elementor Page Builder any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2020-13126
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
Published 2020-05-17 · Modified
9.9EPSS 0.086
CVE-2020-7055
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
Published 2020-04-22 · Modified
9.9EPSS 0.031
CVE-2017-18596
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
Published 2019-09-10 · Modified
8.8EPSS 0.014
CVE-2025-3076
Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-06-10 · Analyzed
6.4EPSS 0.002
CVE-2018-18379
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.
Published 2019-10-07 · Modified
6.1EPSS 0.013
CVE-2020-13864
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
Published 2020-06-05 · Modified
5.4EPSS 0.008
CVE-2020-13865
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
Published 2020-06-05 · Modified
5.4EPSS 0.008
CVE-2020-20406
A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.
Published 2020-09-16 · Modified
5.4EPSS 0.007