Elementor is a widely deployed WordPress page-builder platform whose vulnerability footprint, while concentrated in a narrow product line, reflects its prominence across web-design and small-business hosting environments. The vendor's disclosures center on its core page-builder and companion products such as Elementor Pro and Site Mailer, with a durable signal of web-application weakness classes including cross-site scripting, unrestricted file uploads, path traversal, and authorization bypass that are endemic to user-facing website-construction tools. Vulnerabilities affecting the vendor display a meaningful tendency toward serious severity outcomes and often acquire public exploit availability, reflecting both the accessibility of the platform and the web-tier attack surface it presents. Defenders should treat Elementor updates and plugin patches as integral to WordPress site hygiene, particularly where the platform is exposed to untrusted content creation or administrative users; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elementor over time
Signals from CVEs in this vendor scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1329HIGH The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboa | Apr 19, 2022 | 8.8 | 89 | NO | YES |
CVE-2021-24891MEDIUM The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting | Nov 23, 2021 | 6.1 | 44 | NO | YES |
CVE-2022-29455MEDIUM DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions. | Jun 13, 2022 | 6.1 | 41 | NO | YES |
CVE-2023-48777HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1. | Mar 26, 2024 | 8.8 | 40 | NO | YES |
CVE-2023-3124HIGH The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and i | Jun 7, 2023 | 8.8 | 35 | NO | NO |
CVE-2020-26596HIGH The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed t | Oct 7, 2020 | 8.8 | 31 | NO | NO |
CVE-2020-7055CRITICAL An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP arc | Apr 22, 2020 | 9.9 | 31 | NO | NO |
CVE-2023-47504CRITICAL Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Bu | Apr 24, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-47505MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects E | Nov 30, 2023 | 5.4 | 29 | NO | NO |
CVE-2022-4953MEDIUM The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that | Aug 14, 2023 | 6.1 | 28 | NO | YES |
Signals from CVEs in this vendor scope (55 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elementor.
Media articles that mention a CVE ID that affects a product developed by Elementor — matched by CVE ID, not by vendor name.