Elementor
Elementor Website Builder: vulnerabilidades y CVE
Elementor Website Builder tiene 37 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE37
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-8081 | Media (4.9) | 0.51% | — | 12 ago 2025 | The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This… |
| CVE-2025-3075 | Media (5.4) | 0.17% | — | 29 jul 2025 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0… |
| CVE-2024-54444 | Media (5.4) | 0.29% | — | 25 feb 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows Stored XSS.This issue affects Elementor Website Builder: from… |
| CVE-2024-13445 | Media (5.4) | 0.28% | — | 20 feb 2025 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due… |
| CVE-2024-8494 | Media (6.5) | 0.31% | — | 30 ene 2025 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 via the 'elementor-template' shortcode. This makes it possible for… |
| CVE-2024-10453 | Media (5.4) | 0.32% | — | 21 dic 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to… |
| CVE-2024-8236 | Media (5.4) | 0.37% | — | 26 nov 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due… |
| CVE-2024-6757 | Media (4.3) | 0.40% | — | 15 oct 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it… |
| CVE-2024-5416 | Media (5.4) | 0.39% | — | 11 sept 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due… |
| CVE-2024-37437 | Media (5.4) | 0.34% | — | 9 jul 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.This issue affects Elementor Website Builder: from n/a through <=… |
| CVE-2023-33922 | Media (4.3) | 0.34% | — | 11 jun 2024 | Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2. |
| CVE-2024-4619 | Media (5.4) | 0.40% | — | 21 may 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due… |
| CVE-2024-24934 | Alta (8.1) | 0.71% | — | 17 may 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website… |
| CVE-2024-4107 | Media (5.4) | 0.42% | — | 14 may 2024 | The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in versions up to, and including, 3.21.0 due to insufficient… |
| CVE-2023-47504 | Crítica (9.8) | 1.5% | — | 24 abr 2024 | Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4. |
| CVE-2024-2117 | Media (5.4) | 0.46% | — | 9 abr 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to… |
| CVE-2024-2120 | Media (5.4) | 0.34% | — | 27 mar 2024 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Navigation widget in all versions up to, and including, 3.20.1 due to insufficient input… |
| CVE-2023-48777 | Alta (8.8) | 4.1% | — | 26 mar 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1. |
| CVE-2024-0506 | Media (5.4) | 0.46% | — | 29 feb 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to,… |
| CVE-2023-47505 | Media (5.4) | 25% | — | 30 nov 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4. |
| CVE-2022-4953 | Media (6.1) | 3.4% | — | 14 ago 2023 | The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs. |
| CVE-2020-36703 | Media (5.4) | 0.48% | — | 7 jun 2023 | The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the… |
| CVE-2023-0329 | Alta (7.2) | 20% | — | 30 may 2023 | The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable… |
| CVE-2022-29455 | Media (6.1) | 24% | — | 13 jun 2022 | DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions. |
| CVE-2022-1329 | Alta (8.8) | 93% | — | 19 abr 2022 | The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it… |
| CVE-2021-24891 | Media (6.1) | 25% | — | 23 nov 2021 | The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue. |
| CVE-2021-24206 | Media (5.4) | 0.75% | — | 5 abr 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html… |
| CVE-2021-24205 | Media (5.4) | 0.75% | — | 5 abr 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags,… |
| CVE-2021-24204 | Media (5.4) | 0.75% | — | 5 abr 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html… |
| CVE-2021-24203 | Media (5.4) | 0.75% | — | 5 abr 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it… |