« Back to list

Elementor

Elementor Page Builder: vulnerabilities and CVEs

Elementor Page Builder has 8 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months0
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-3076Medium (5.4)0.19%—Jun 10, 2025
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions up to, and including, 3.29.0 due to insufficient input sanitization and…
CVE-2020-20406Medium (5.4)0.70%—Sep 16, 2020
A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.
CVE-2020-13865Medium (5.4)0.76%—Jun 5, 2020
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the…
CVE-2020-13864Medium (5.4)0.76%—Jun 5, 2020
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
CVE-2020-13126Critical (9.9)8.6%—May 17, 2020
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary…
CVE-2020-7055Critical (9.9)3.1%—Apr 22, 2020
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
CVE-2018-18379Medium (6.1)1.3%—Oct 7, 2019
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.
CVE-2017-18596High (8.8)1.4%—Sep 10, 2019
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.

Other products by Elementor