Elementor / Website Builder
38 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-8081 | Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import | MEDIUM | 4.9 | Aug 12, 2025 |
| CVE-2025-3075 | Elementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | MEDIUM | 6.4 | Jul 29, 2025 |
| CVE-2024-54444 | WordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Feb 25, 2025 |
| CVE-2024-13445 | Elementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | MEDIUM | 6.4 | Feb 20, 2025 |
| CVE-2024-8494 | Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode | MEDIUM | 6.5 | Jan 30, 2025 |
| CVE-2024-10453 | Elementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings | MEDIUM | 6.4 | Dec 21, 2024 |
| CVE-2024-8236 | Elementor Website Builder – More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | MEDIUM | 6.4 | Nov 26, 2024 |
| CVE-2024-6757 | Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function | MEDIUM | 4.3 | Oct 15, 2024 |
| CVE-2024-5416 | Elementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple… | MEDIUM | 5.4 | Sep 11, 2024 |
| CVE-2024-37437 | WordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerability | MEDIUM | 5.5 | Jul 9, 2024 |
| CVE-2023-33922 | WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability | MEDIUM | 4.3 | Jun 11, 2024 |
| CVE-2024-4619 | Elementor Website Builder – More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | MEDIUM | 6.4 | May 21, 2024 |
| CVE-2024-24934 | WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability | HIGH | 8.5 | May 17, 2024 |
| CVE-2024-4107 | Elementor Website Builder Pro <= 3.21.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | MEDIUM | 6.4 | May 9, 2024 |
| CVE-2023-47504 | WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability | CRITICAL | 9.8 | Apr 24, 2024 |
| CVE-2024-2117 | Elementor Website Builder – More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget | MEDIUM | 6.4 | Apr 9, 2024 |
| CVE-2024-2120 | Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation | MEDIUM | 5.4 | Mar 27, 2024 |
| CVE-2024-2781 | Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tag | MEDIUM | 6.4 | Mar 27, 2024 |
| CVE-2023-48777 | WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability | CRITICAL | 9.9 | Mar 26, 2024 |
| CVE-2024-0506 | Elementor Website Builder – More than Just a Page Builder <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt | MEDIUM | 6.4 | Feb 20, 2024 |
| CVE-2023-47505 | WordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS) | MEDIUM | 6.5 | Nov 30, 2023 |
| CVE-2022-4953 | Elementor < 3.5.5 - Iframe Injection | MEDIUM | 6.1 | Aug 14, 2023 |
| CVE-2020-36703 | Elementor Website Builder <= 2.9.7 - Authenticated Stored Cross-Site Scripting | MEDIUM | 6.4 | Jun 7, 2023 |
| CVE-2023-0329 | Elementor Website Builder < 3.12.2 - Admin+ SQLi | HIGH | 7.2 | May 30, 2023 |
| CVE-2022-29455 | WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability | MEDIUM | 6.1 | Jun 13, 2022 |
Showing 1 to 25 of 38 CVEs