Elementor records
54 published records for vendor elementor.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 1.9%
- Pre-auth RCE
- 0
- With a fix record
- 20.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')36
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-862 Missing Authorization3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-269 Improper Privilege Management2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
54 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2022-1329Weaponized | Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Executionelementor · website builder · CWE-434 | High8.8 | — | 92.7% | Apr 19, 2022 |
42Plan | CVE-2023-3124Proof of concept | Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_optionelementor · elementor pro · CWE-862 | High8.8 | — | 22.7% | Jun 6, 2023 |
42Plan | CVE-2020-13126Proof of concept | An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVEelementor · elementor page builder · CWE-434 | Critical9.9 | — | 8.6% | May 16, 2020 |
40Plan | CVE-2020-7055No exploit | An issue was discovered in Elementor 2.7.4.elementor · elementor page builder · CWE-434 | Critical9.9 | — | 3.1% | Apr 22, 2020 |
40Plan | CVE-2020-7109No exploit | The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.elementor · website builder | Critical9.8 | — | 1.7% | Jan 22, 2020 |
39Monitor | CVE-2023-47504Proof of concept | WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerabilityelementor · website builder · CWE-287 | Critical9.8 | — | 1.5% | Apr 24, 2024 |
37Monitor | CVE-2020-26596No exploit | The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code elementor · elementor pro · CWE-269 | High8.8 | — | 5.7% | Oct 7, 2020 |
36Monitor | CVE-2023-48777Proof of concept | WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerabilityelementor · website builder · CWE-434 | High8.8 | — | 4.1% | Mar 26, 2024 |
35Monitor | CVE-2017-18596No exploit | The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.elementor · elementor page builder · CWE-269 | High8.8 | — | 1.4% | Sep 10, 2019 |
34Monitor | CVE-2023-0329No exploit | Elementor Website Builder < 3.12.2 - Admin+ SQLielementor · website builder · CWE-89 | High7.2 | — | 19.7% | May 30, 2023 |
32Monitor | CVE-2021-24891Proof of concept | Elementor < 3.4.8 - DOM Cross-Site-Scriptingelementor · website builder · CWE-79 | Medium6.1 | — | 25.1% | Nov 23, 2021 |
32Monitor | CVE-2024-24934No exploit | WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerabilityelementor · website builder · CWE-22 | High8.1 | — | 0.7% | May 17, 2024 |
31Monitor | CVE-2022-29455Proof of concept | WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerabilityelementor · website builder · CWE-79 | Medium6.1 | — | 23.7% | Jun 13, 2022 |
29Monitor | CVE-2023-47505No exploit | WordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS)elementor · website builder · CWE-79 | Medium5.4 | — | 25.3% | Nov 30, 2023 |
28Monitor | CVE-2025-1319No exploit | Site Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scriptingelementor · site mailer · CWE-79 | High7.2 | — | 0.4% | Feb 28, 2025 |
26Monitor | CVE-2020-20634No exploit | Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature.elementor · website builder | Medium6.5 | — | 1.0% | Aug 21, 2020 |
26Monitor | CVE-2024-8494No exploit | Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcodeelementor · website builder · CWE-200 | Medium6.5 | — | 0.3% | Jan 30, 2025 |
25Monitor | CVE-2022-4953Proof of concept | Elementor < 3.5.5 - Iframe Injectionelementor · website builder · CWE-80 | Medium6.1 | — | 3.4% | Aug 14, 2023 |
24Monitor | CVE-2018-18379No exploit | The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.elementor · elementor page builder · CWE-79 | Medium6.1 | — | 1.3% | Oct 7, 2019 |
24Monitor | CVE-2020-36171No exploit | The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.elementor · website builder · CWE-79 | Medium6.1 | — | 0.8% | Jan 6, 2021 |
24Monitor | CVE-2024-35656No exploit | WordPress Elementor Pro <= 3.21.2 - Reflected Cross Site Scripting (XSS) vulnerabilityelementor · elementor pro · CWE-79 | Medium6.1 | — | 0.3% | Jul 22, 2024 |
21Monitor | CVE-2020-8426No exploit | The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page.elementor · website builder · CWE-79 | Medium5.4 | — | 1.3% | Jan 28, 2020 |
21Monitor | CVE-2020-13864No exploit | The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability.elementor · elementor page builder · CWE-79 | Medium5.4 | — | 0.8% | Jun 5, 2020 |
21Monitor | CVE-2020-13865No exploit | The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities.elementor · elementor page builder · CWE-79 | Medium5.4 | — | 0.8% | Jun 5, 2020 |
21Monitor | CVE-2021-24205No exploit | Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widgetelementor · website builder · CWE-79 | Medium5.4 | — | 0.8% | Apr 5, 2021 |
- CVE-2022-132963This week
Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution
HighCVSS 8.8WeaponizedEPSS 93%elementor · website builderApr 19, 2022
- CVE-2023-312442Plan
Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option
HighCVSS 8.8Proof of conceptEPSS 23%elementor · elementor proJun 6, 2023
- CVE-2020-1312642Plan
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE
CriticalCVSS 9.9Proof of conceptEPSS 9%elementor · elementor page builderMay 16, 2020
- CVE-2020-705540Plan
An issue was discovered in Elementor 2.7.4.
CriticalCVSS 9.9No exploitEPSS 3%elementor · elementor page builderApr 22, 2020
- CVE-2020-710940Plan
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
CriticalCVSS 9.8No exploitEPSS 2%elementor · website builderJan 22, 2020
- CVE-2023-4750439Monitor
WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 1%elementor · website builderApr 24, 2024
- CVE-2020-2659637Monitor
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code
HighCVSS 8.8No exploitEPSS 6%elementor · elementor proOct 7, 2020
- CVE-2023-4877736Monitor
WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability
HighCVSS 8.8Proof of conceptEPSS 4%elementor · website builderMar 26, 2024
- CVE-2017-1859635Monitor
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
HighCVSS 8.8No exploitEPSS 1%elementor · elementor page builderSep 10, 2019
- CVE-2023-032934Monitor
Elementor Website Builder < 3.12.2 - Admin+ SQLi
HighCVSS 7.2No exploitEPSS 20%elementor · website builderMay 30, 2023
- CVE-2021-2489132Monitor
Elementor < 3.4.8 - DOM Cross-Site-Scripting
MediumCVSS 6.1Proof of conceptEPSS 25%elementor · website builderNov 23, 2021
- CVE-2024-2493432Monitor
WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability
HighCVSS 8.1No exploitEPSS 1%elementor · website builderMay 17, 2024
- CVE-2022-2945531Monitor
WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1Proof of conceptEPSS 24%elementor · website builderJun 13, 2022
- CVE-2023-4750529Monitor
WordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 25%elementor · website builderNov 30, 2023
- CVE-2025-131928Monitor
Site Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting
HighCVSS 7.2No exploitEPSS 0%elementor · site mailerFeb 28, 2025
- CVE-2020-2063426Monitor
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature.
MediumCVSS 6.5No exploitEPSS 1%elementor · website builderAug 21, 2020
- CVE-2024-849426Monitor
Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode
MediumCVSS 6.5No exploitEPSS 0%elementor · website builderJan 30, 2025
- CVE-2022-495325Monitor
Elementor < 3.5.5 - Iframe Injection
MediumCVSS 6.1Proof of conceptEPSS 3%elementor · website builderAug 14, 2023
- CVE-2018-1837924Monitor
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.
MediumCVSS 6.1No exploitEPSS 1%elementor · elementor page builderOct 7, 2019
- CVE-2020-3617124Monitor
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
MediumCVSS 6.1No exploitEPSS 1%elementor · website builderJan 6, 2021
- CVE-2024-3565624Monitor
WordPress Elementor Pro <= 3.21.2 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%elementor · elementor proJul 22, 2024
- CVE-2020-842621Monitor
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page.
MediumCVSS 5.4No exploitEPSS 1%elementor · website builderJan 28, 2020
- CVE-2020-1386421Monitor
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability.
MediumCVSS 5.4No exploitEPSS 1%elementor · elementor page builderJun 5, 2020
- CVE-2020-1386521Monitor
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities.
MediumCVSS 5.4No exploitEPSS 1%elementor · elementor page builderJun 5, 2020
- CVE-2021-2420521Monitor
Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget
MediumCVSS 5.4No exploitEPSS 1%elementor · website builderApr 5, 2021