VendorsElementorelementor_proany version
Vulnerabilities

Elementor Elementor Pro any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-26596
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.
Published 2020-10-07 · Modified
9.0EPSS 0.057
CVE-2023-3124
Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option
Published 2023-06-07 · Modified
8.8EPSS 0.227
CVE-2024-35656
WordPress Elementor Pro <= 3.21.2 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-07-22 · Modified
7.1EPSS 0.003
CVE-2024-1364
Elementor Website Builder Pro <= 3.20.1 - Authententicated (Contributor+) Stored Cross-Site Scripting
Published 2024-03-27 · Modified
6.4EPSS 0.003
CVE-2024-1521
Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Widget SVGZ File Upload
Published 2024-03-27 · Modified
6.4EPSS 0.003
CVE-2024-2781
Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tag
Published 2024-03-27 · Modified
6.4EPSS 0.003
CVE-2024-2121
Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-03-27 · Modified
5.4EPSS 0.003