Elementor Page Builder
Elementor · 8 CVEs
Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Jun 10, 2025
A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2…
Sep 16, 2020
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An autho…
Jun 5, 2020
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user ca…
Jun 5, 2020
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in…
May 17, 2020
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates functio…
Apr 22, 2020
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has…
Oct 7, 2019
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
Sep 10, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-3076 | Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | MEDIUM | 0.19% | Jun 10, 2025 |
| CVE-2020-20406 | A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by i… | MEDIUM | 0.70% | Sep 16, 2020 |
| CVE-2020-13865 | The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in s… | MEDIUM | 0.76% | Jun 5, 2020 |
| CVE-2020-13864 | The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored X… | MEDIUM | 0.76% | Jun 5, 2020 |
| CVE-2020-13126 | An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An att… | CRITICAL | 8.57% | May 17, 2020 |
| CVE-2020-7055 | An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code… | CRITICAL | 3.07% | Apr 22, 2020 |
| CVE-2018-18379 | The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS. | MEDIUM | 1.30% | Oct 7, 2019 |
| CVE-2017-18596 | The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions. | HIGH | 1.38% | Sep 10, 2019 |
Showing 1 to 8 of 8 CVEs