HomeWordPress vulnerabilitiesElementor Website Builder
Elementor Website Builder vulnerabilities
Elementor Website Builder has 26 known vulnerabilities in this database. The most recent published record is dated 20 Jul 2026.
- Known vulnerabilities
- 26
- Active installs
- 10m+
- Latest version
- 4.3.3
- Last updated
- 30 Sep 2026
- Most recent
- 20 Jul 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-8825 | Medium 4.9 | Before 4.1.4 | Fixed in 4.1.4 | 20 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-6127 | Medium 6.4 | Up to 4.0.4 | Fixed in a later version (latest 4.3.3) | 1 May 2026 |
| Cross-site scripting (XSS) CVE-2025-14732 | Medium 6.4 | Up to 3.35.5 | Fixed in a later version (latest 4.3.3) | 8 Apr 2026 |
| Sensitive data exposure CVE-2026-1206 | Medium 4.3 | Up to 3.35.7 | Fixed in a later version (latest 4.3.3) | 26 Mar 2026 |
| Cross-site scripting (XSS) CVE-2025-11220 | Medium 6.4 | Up to 3.33.3 | Fixed in a later version (latest 4.3.3) | 16 Dec 2025 |
| Arbitrary file read CVE-2025-8081 | Medium 4.9 | Before 3.30.3 | Fixed in 3.30.3 | 12 Aug 2025 |
| Cross-site scripting (XSS) CVE-2025-4566 | Medium 6.4 | Up to 3.30.2 | Fixed in a later version (latest 4.3.3) | 29 Jul 2025 |
| Cross-site scripting (XSS) CVE-2025-3075 | Medium 6.4 | Before 3.29.1 | Fixed in 3.29.1 | 29 Jul 2025 |
| Cross-site scripting (XSS) CVE-2024-13445 | Medium 6.4 | Before 3.27.5 | Fixed in 3.27.5 | 20 Feb 2025 |
| Cross-site scripting (XSS) CVE-2024-10453 | Medium 6.4 | Up to 3.25.9 | Fixed in a later version (latest 4.3.3) | 21 Dec 2024 |
| Cross-site scripting (XSS) CVE-2024-8236 | Medium 6.4 | Up to 3.25.7 | Fixed in a later version (latest 4.3.3) | 26 Nov 2024 |
| Sensitive data exposure CVE-2024-6757 | Medium 4.3 | Before 3.24.6 | Fixed in 3.24.6 | 15 Oct 2024 |
| Cross-site scripting (XSS) CVE-2024-5416 | Medium 5.4 | Before 3.24.0 | Fixed in 3.24.0 | 11 Sep 2024 |
| Cross-site scripting (XSS) CVE-2024-4619 | Medium 6.4 | Before 3.21.5 | Fixed in 3.21.5 | 21 May 2024 |
| Cross-site scripting (XSS) CVE-2024-2117 | Medium 6.4 | Before 3.20.3 | Fixed in 3.20.3 | 9 Apr 2024 |
| Cross-site scripting (XSS) CVE-2024-0506 | Medium 6.4 | Before 3.19.0 | Fixed in 3.19.0 | 29 Feb 2024 |
| Security weakness CVE-2022-4953 | Medium 6.1 | Before 3.5.5 | Fixed in 3.5.5 | 14 Aug 2023 |
| Cross-site scripting (XSS) CVE-2020-36703 | Medium 6.4 | Up to 2.9.7 | Fixed in a later version (latest 4.3.3) | 7 Jun 2023 |
| SQL injection CVE-2023-0329 | High 7.2 | Before 3.12.2 | Fixed in 3.12.2 | 30 May 2023 |
| Remote code execution CVE-2022-1329 | High 8.8 | Up to 3.6.2 | Fixed in a later version (latest 4.3.3) | 19 Apr 2022 |
| Cross-site scripting (XSS) CVE-2021-24891 | Medium 6.1 | Before 3.4.8 | Fixed in 3.4.8 | 23 Nov 2021 |
| Cross-site scripting (XSS) CVE-2020-36171 | Medium 6.1 | Before 3.0.14 | Fixed in 3.0.14 | 6 Jan 2021 |
| Cross-site scripting (XSS) CVE-2020-15020 | Medium 5.4 | Up to 2.9.13 | Fixed in a later version (latest 4.3.3) | 31 Aug 2020 |
| Cross-site scripting (XSS) CVE-2020-8426 | Medium 5.4 | Before 2.8.5 | Fixed in 2.8.5 | 28 Jan 2020 |
| Security weakness CVE-2020-7109 | Critical 9.8 | Before 2.8.4 | Fixed in 2.8.4 | 22 Jan 2020 |
| Privilege escalation CVE-2017-18596 | High 8.8 | Before 1.8.0 | Fixed in 1.8.0 | 10 Sep 2019 |
Read the published descriptions
- CVE-2026-8825, 20 Jul 2026
- The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators). CVE record
- CVE-2026-6127, 1 May 2026
- The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0.4. This is due to insufficient input sanitization when processing form-encoded REST API requests. The plugin registers the _elementor_data meta field with show_in_rest but omits a sanitize_callback, relying instead on a rest_pre_insert_post filter (sanitize_post_data function) that only sanitizes JSON-encoded request bodies. When a contributor sends a form-encoded PATCH request to the WordPress REST API, the json_decode() call on the raw body returns null, causing all sanitization to be skipped. The unsanitized data is then stored via update_post_meta() and later output without escaping through multiple widget sinks including the HTML widget's print_unescaped_setting() function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-14732, 8 Apr 2026
- The Elementor Website Builder - More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-1206, 26 Mar 2026
- The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats non-published templates as readable without verifying edit capabilities. This makes it possible for authenticated attackers, with contributor-level access and above, to read private or draft Elementor template content via the 'template_id' supplied to the 'get_template_data' action of the 'elementor_ajax' endpoint. CVE record
- CVE-2025-11220, 16 Dec 2025
- The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-8081, 12 Aug 2025
- The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. CVE record
- CVE-2025-4566, 29 Jul 2025
- The Elementor Website Builder - More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This attack affects only Chrome/Edge browsers CVE record
- CVE-2025-3075, 29 Jul 2025
- The Elementor Website Builder - More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts sites with 'Element Caching' enabled. CVE record
- CVE-2024-13445, 20 Feb 2025
- The Elementor Website Builder - More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-10453, 21 Dec 2024
- The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-8236, 26 Nov 2024
- The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-6757, 15 Oct 2024
- The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts. CVE record
- CVE-2024-5416, 11 Sep 2024
- The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in Elementor Editor pages. This was partially patched in version 3.23.2. CVE record
- CVE-2024-4619, 21 May 2024
- The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-2117, 9 Apr 2024
- The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-0506, 29 Feb 2024
- The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2022-4953, 14 Aug 2023
- The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs. CVE record
- CVE-2020-36703, 7 Jun 2023
- The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts. CVE record
- CVE-2023-0329, 30 May 2023
- The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role. CVE record
- CVE-2022-1329, 19 Apr 2022
- The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2. CVE record
- CVE-2021-24891, 23 Nov 2021
- The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue. CVE record
- CVE-2020-36171, 6 Jan 2021
- The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads. CVE record
- CVE-2020-15020, 31 Aug 2020
- An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field. CVE record
- CVE-2020-8426, 28 Jan 2020
- The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user. CVE record
- CVE-2020-7109, 22 Jan 2020
- The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. CVE record
- CVE-2017-18596, 10 Sep 2019
- The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions. CVE record
What to do if you run Elementor Website Builder
If you run Elementor Website Builder, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Elementor Website Builder vulnerabilities
Free. We email you when a new vulnerability is published for Elementor Website Builder, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.