Skip to content
Noroxi

Elementor records

54 published records for vendor elementor.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

54 records
  • CVE-2022-1329
    63This week

    Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution

    HighCVSS 8.8WeaponizedEPSS 93%

    elementor · website builderApr 19, 2022

  • Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option

    HighCVSS 8.8Proof of conceptEPSS 23%

    elementor · elementor proJun 6, 2023

  • An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE

    CriticalCVSS 9.9Proof of conceptEPSS 9%

    elementor · elementor page builderMay 16, 2020

  • An issue was discovered in Elementor 2.7.4.

    CriticalCVSS 9.9No exploitEPSS 3%

    elementor · elementor page builderApr 22, 2020

  • The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

    CriticalCVSS 9.8No exploitEPSS 2%

    elementor · website builderJan 22, 2020

  • WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    elementor · website builderApr 24, 2024

  • The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code

    HighCVSS 8.8No exploitEPSS 6%

    elementor · elementor proOct 7, 2020

  • WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability

    HighCVSS 8.8Proof of conceptEPSS 4%

    elementor · website builderMar 26, 2024

  • The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.

    HighCVSS 8.8No exploitEPSS 1%

    elementor · elementor page builderSep 10, 2019

  • CVE-2023-0329
    34Monitor

    Elementor Website Builder < 3.12.2 - Admin+ SQLi

    HighCVSS 7.2No exploitEPSS 20%

    elementor · website builderMay 30, 2023

  • Elementor < 3.4.8 - DOM Cross-Site-Scripting

    MediumCVSS 6.1Proof of conceptEPSS 25%

    elementor · website builderNov 23, 2021

  • WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability

    HighCVSS 8.1No exploitEPSS 1%

    elementor · website builderMay 17, 2024

  • WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability

    MediumCVSS 6.1Proof of conceptEPSS 24%

    elementor · website builderJun 13, 2022

  • WordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 25%

    elementor · website builderNov 30, 2023

  • CVE-2025-1319
    28Monitor

    Site Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting

    HighCVSS 7.2No exploitEPSS 0%

    elementor · site mailerFeb 28, 2025

  • Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature.

    MediumCVSS 6.5No exploitEPSS 1%

    elementor · website builderAug 21, 2020

  • CVE-2024-8494
    26Monitor

    Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode

    MediumCVSS 6.5No exploitEPSS 0%

    elementor · website builderJan 30, 2025

  • CVE-2022-4953
    25Monitor

    Elementor < 3.5.5 - Iframe Injection

    MediumCVSS 6.1Proof of conceptEPSS 3%

    elementor · website builderAug 14, 2023

  • The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    elementor · elementor page builderOct 7, 2019

  • The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.

    MediumCVSS 6.1No exploitEPSS 1%

    elementor · website builderJan 6, 2021

  • WordPress Elementor Pro <= 3.21.2 - Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    elementor · elementor proJul 22, 2024

  • CVE-2020-8426
    21Monitor

    The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page.

    MediumCVSS 5.4No exploitEPSS 1%

    elementor · website builderJan 28, 2020

  • The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability.

    MediumCVSS 5.4No exploitEPSS 1%

    elementor · elementor page builderJun 5, 2020

  • The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities.

    MediumCVSS 5.4No exploitEPSS 1%

    elementor · elementor page builderJun 5, 2020

  • Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget

    MediumCVSS 5.4No exploitEPSS 1%

    elementor · website builderApr 5, 2021