Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Elementor

First CVE: Sep 10, 2019Active for: 7 yearsTotal CVEs: 55
34.7
VTI Score
Medium

Elementor is a widely deployed WordPress page-builder platform whose vulnerability footprint, while concentrated in a narrow product line, reflects its prominence across web-design and small-business hosting environments. The vendor's disclosures center on its core page-builder and companion products such as Elementor Pro and Site Mailer, with a durable signal of web-application weakness classes including cross-site scripting, unrestricted file uploads, path traversal, and authorization bypass that are endemic to user-facing website-construction tools. Vulnerabilities affecting the vendor display a meaningful tendency toward serious severity outcomes and often acquire public exploit availability, reflecting both the accessibility of the platform and the web-tier attack surface it presents. Defenders should treat Elementor updates and plugin patches as integral to WordPress site hygiene, particularly where the platform is exposed to untrusted content creation or administrative users; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
55
Total CVEs
More Total CVEs than 99% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Elementor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 10, 2019
6 years ago
Most Recent CVE
Aug 12, 2025
346 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-1329HIGH
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboa
Apr 19, 20228.889NOYES
CVE-2021-24891MEDIUM
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting
Nov 23, 20216.144NOYES
CVE-2022-29455MEDIUM
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
Jun 13, 20226.141NOYES
CVE-2023-48777HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.
Mar 26, 20248.840NOYES
CVE-2023-3124HIGH
The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and i
Jun 7, 20238.835NONO
CVE-2020-26596HIGH
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed t
Oct 7, 20208.831NONO
CVE-2020-7055CRITICAL
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP arc
Apr 22, 20209.931NONO
CVE-2023-47504CRITICAL
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Bu
Apr 24, 20249.829NONO
CVE-2023-47505MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects E
Nov 30, 20235.429NONO
CVE-2022-4953MEDIUM
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that
Aug 14, 20236.128NOYES
View all 55 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products55 CVEs
78%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network55 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low55 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (34.5%)
Unknown0 (0.0%)
Required36 (65.5%)
Privileges Required
Low43 (78.2%)
High2 (3.6%)
None10 (18.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 97th percentile
Nuclei
4 CVEs
7.3% of CVEs· 96th percentile
ExploitDB
1 CVE
1.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Elementor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Elementor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Elementor's Products

View all 4 CNAs →

Top CWEs