Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesElementor Website Builder

Elementor Website Builder vulnerabilities

Elementor Website Builder has 26 known vulnerabilities in this database. The most recent published record is dated 20 Jul 2026.

Known vulnerabilities
26
Active installs
10m+
Latest version
4.3.3
Last updated
30 Sep 2026
Most recent
20 Jul 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2026-8825
Medium 4.9Before 4.1.4Fixed in 4.1.420 Jul 2026
Cross-site scripting (XSS)
CVE-2026-6127
Medium 6.4Up to 4.0.4Fixed in a later version (latest 4.3.3)1 May 2026
Cross-site scripting (XSS)
CVE-2025-14732
Medium 6.4Up to 3.35.5Fixed in a later version (latest 4.3.3)8 Apr 2026
Sensitive data exposure
CVE-2026-1206
Medium 4.3Up to 3.35.7Fixed in a later version (latest 4.3.3)26 Mar 2026
Cross-site scripting (XSS)
CVE-2025-11220
Medium 6.4Up to 3.33.3Fixed in a later version (latest 4.3.3)16 Dec 2025
Arbitrary file read
CVE-2025-8081
Medium 4.9Before 3.30.3Fixed in 3.30.312 Aug 2025
Cross-site scripting (XSS)
CVE-2025-4566
Medium 6.4Up to 3.30.2Fixed in a later version (latest 4.3.3)29 Jul 2025
Cross-site scripting (XSS)
CVE-2025-3075
Medium 6.4Before 3.29.1Fixed in 3.29.129 Jul 2025
Cross-site scripting (XSS)
CVE-2024-13445
Medium 6.4Before 3.27.5Fixed in 3.27.520 Feb 2025
Cross-site scripting (XSS)
CVE-2024-10453
Medium 6.4Up to 3.25.9Fixed in a later version (latest 4.3.3)21 Dec 2024
Cross-site scripting (XSS)
CVE-2024-8236
Medium 6.4Up to 3.25.7Fixed in a later version (latest 4.3.3)26 Nov 2024
Sensitive data exposure
CVE-2024-6757
Medium 4.3Before 3.24.6Fixed in 3.24.615 Oct 2024
Cross-site scripting (XSS)
CVE-2024-5416
Medium 5.4Before 3.24.0Fixed in 3.24.011 Sep 2024
Cross-site scripting (XSS)
CVE-2024-4619
Medium 6.4Before 3.21.5Fixed in 3.21.521 May 2024
Cross-site scripting (XSS)
CVE-2024-2117
Medium 6.4Before 3.20.3Fixed in 3.20.39 Apr 2024
Cross-site scripting (XSS)
CVE-2024-0506
Medium 6.4Before 3.19.0Fixed in 3.19.029 Feb 2024
Security weakness
CVE-2022-4953
Medium 6.1Before 3.5.5Fixed in 3.5.514 Aug 2023
Cross-site scripting (XSS)
CVE-2020-36703
Medium 6.4Up to 2.9.7Fixed in a later version (latest 4.3.3)7 Jun 2023
SQL injection
CVE-2023-0329
High 7.2Before 3.12.2Fixed in 3.12.230 May 2023
Remote code execution
CVE-2022-1329
High 8.8Up to 3.6.2Fixed in a later version (latest 4.3.3)19 Apr 2022
Cross-site scripting (XSS)
CVE-2021-24891
Medium 6.1Before 3.4.8Fixed in 3.4.823 Nov 2021
Cross-site scripting (XSS)
CVE-2020-36171
Medium 6.1Before 3.0.14Fixed in 3.0.146 Jan 2021
Cross-site scripting (XSS)
CVE-2020-15020
Medium 5.4Up to 2.9.13Fixed in a later version (latest 4.3.3)31 Aug 2020
Cross-site scripting (XSS)
CVE-2020-8426
Medium 5.4Before 2.8.5Fixed in 2.8.528 Jan 2020
Security weakness
CVE-2020-7109
Critical 9.8Before 2.8.4Fixed in 2.8.422 Jan 2020
Privilege escalation
CVE-2017-18596
High 8.8Before 1.8.0Fixed in 1.8.010 Sep 2019
Read the published descriptions
CVE-2026-8825, 20 Jul 2026
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators). CVE record
CVE-2026-6127, 1 May 2026
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0.4. This is due to insufficient input sanitization when processing form-encoded REST API requests. The plugin registers the _elementor_data meta field with show_in_rest but omits a sanitize_callback, relying instead on a rest_pre_insert_post filter (sanitize_post_data function) that only sanitizes JSON-encoded request bodies. When a contributor sends a form-encoded PATCH request to the WordPress REST API, the json_decode() call on the raw body returns null, causing all sanitization to be skipped. The unsanitized data is then stored via update_post_meta() and later output without escaping through multiple widget sinks including the HTML widget's print_unescaped_setting() function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-14732, 8 Apr 2026
The Elementor Website Builder - More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-1206, 26 Mar 2026
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats non-published templates as readable without verifying edit capabilities. This makes it possible for authenticated attackers, with contributor-level access and above, to read private or draft Elementor template content via the 'template_id' supplied to the 'get_template_data' action of the 'elementor_ajax' endpoint. CVE record
CVE-2025-11220, 16 Dec 2025
The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-8081, 12 Aug 2025
The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. CVE record
CVE-2025-4566, 29 Jul 2025
The Elementor Website Builder - More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This attack affects only Chrome/Edge browsers CVE record
CVE-2025-3075, 29 Jul 2025
The Elementor Website Builder - More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts sites with 'Element Caching' enabled. CVE record
CVE-2024-13445, 20 Feb 2025
The Elementor Website Builder - More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-10453, 21 Dec 2024
The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-8236, 26 Nov 2024
The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-6757, 15 Oct 2024
The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts. CVE record
CVE-2024-5416, 11 Sep 2024
The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in Elementor Editor pages. This was partially patched in version 3.23.2. CVE record
CVE-2024-4619, 21 May 2024
The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2117, 9 Apr 2024
The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-0506, 29 Feb 2024
The Elementor Website Builder - More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2022-4953, 14 Aug 2023
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs. CVE record
CVE-2020-36703, 7 Jun 2023
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts. CVE record
CVE-2023-0329, 30 May 2023
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role. CVE record
CVE-2022-1329, 19 Apr 2022
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2. CVE record
CVE-2021-24891, 23 Nov 2021
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue. CVE record
CVE-2020-36171, 6 Jan 2021
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads. CVE record
CVE-2020-15020, 31 Aug 2020
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field. CVE record
CVE-2020-8426, 28 Jan 2020
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user. CVE record
CVE-2020-7109, 22 Jan 2020
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. CVE record
CVE-2017-18596, 10 Sep 2019
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions. CVE record

What to do if you run Elementor Website Builder

If you run Elementor Website Builder, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Elementor Website Builder vulnerabilities

Free. We email you when a new vulnerability is published for Elementor Website Builder, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support