VendorsElementorwebsite_builderall versions
Vulnerabilities

Elementor Website Builder

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2023-48777
WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability
Published 2024-03-26 · Modified
9.9EPSS 0.041
CVE-2020-7109
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
Published 2020-01-22 · Modified
9.8EPSS 0.017
CVE-2023-47504
WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability
Published 2024-04-24 · Modified
9.8EPSS 0.015
CVE-2022-1329
Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution
Published 2022-04-19 · Modified
8.8EPSS 0.927
CVE-2024-24934
WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability
Published 2024-05-17 · Analyzed
8.5EPSS 0.007
CVE-2023-0329
Elementor Website Builder < 3.12.2 - Admin+ SQLi
Published 2023-05-30 · Modified
7.2EPSS 0.197
CVE-2023-47505
WordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS)
Published 2023-11-30 · Modified
6.5EPSS 0.253
CVE-2020-20634
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
Published 2020-08-21 · Modified
6.5EPSS 0.010
CVE-2024-8494
Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode
Published 2025-01-30 · Analyzed
6.5EPSS 0.003
CVE-2024-54444
WordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerability
Published 2025-02-25 · Modified
6.5EPSS 0.003
CVE-2020-36703
Elementor Website Builder <= 2.9.7 - Authenticated Stored Cross-Site Scripting
Published 2023-06-07 · Modified
6.4EPSS 0.005
CVE-2024-0506
Elementor Website Builder – More than Just a Page Builder <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt
Published 2024-02-20 · Modified
6.4EPSS 0.005
CVE-2024-2117
Elementor Website Builder – More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget
Published 2024-04-09 · Modified
6.4EPSS 0.005
CVE-2024-4107
Elementor Website Builder Pro <= 3.21.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Published 2024-05-09 · Modified
6.4EPSS 0.004
CVE-2024-4619
Elementor Website Builder – More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Published 2024-05-21 · Modified
6.4EPSS 0.004
CVE-2024-8236
Elementor Website Builder – More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-11-26 · Analyzed
6.4EPSS 0.004
CVE-2024-10453
Elementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings
Published 2024-12-21 · Analyzed
6.4EPSS 0.003
CVE-2024-13445
Elementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-02-20 · Analyzed
6.4EPSS 0.003
CVE-2025-3075
Elementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-07-29 · Analyzed
6.4EPSS 0.002
CVE-2021-24891
Elementor < 3.4.8 - DOM Cross-Site-Scripting
Published 2021-11-23 · Modified
6.1EPSS 0.251
CVE-2022-29455
WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability
Published 2022-06-13 · Modified
6.1EPSS 0.237
CVE-2022-4953
Elementor < 3.5.5 - Iframe Injection
Published 2023-08-14 · Modified
6.11 PoCEPSS 0.034
CVE-2020-36171
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
Published 2021-01-06 · Modified
6.1EPSS 0.008
CVE-2024-37437
WordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerability
Published 2024-07-09 · Modified
5.5EPSS 0.003
CVE-2020-8426
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
Published 2020-01-28 · Modified
5.4EPSS 0.013
CVE-2021-24205
Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget
Published 2021-04-05 · Modified
5.4EPSS 0.008
CVE-2021-24204
Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget
Published 2021-04-05 · Modified
5.4EPSS 0.007
CVE-2021-24201
Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element
Published 2021-04-05 · Modified
5.4EPSS 0.007
CVE-2021-24202
Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget
Published 2021-04-05 · Modified
5.4EPSS 0.007
CVE-2021-24206
Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget
Published 2021-04-05 · Modified
5.4EPSS 0.007
CVE-2021-24203
Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget
Published 2021-04-05 · Modified
5.4EPSS 0.007
CVE-2020-15020
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
Published 2020-08-31 · Modified
5.4EPSS 0.007
CVE-2024-5416
Elementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets
Published 2024-09-11 · Analyzed
5.4EPSS 0.004
CVE-2024-2120
Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation
Published 2024-03-27 · Modified
5.4EPSS 0.003
CVE-2025-8081
Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import
Published 2025-08-12 · Analyzed
4.9EPSS 0.005
CVE-2024-6757
Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function
Published 2024-10-15 · Analyzed
4.3EPSS 0.004
CVE-2023-33922
WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability
Published 2024-06-11 · Modified
4.3EPSS 0.003