Plugin Vulnerability Hub
Plugin 45 known issues Latest disclosed Mar 25, 2026

Elementor Website Builder – More Than Just a Page Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin Elementor Website Builder – More Than Just a Page Builder (`elementor`), including severity, CVE references, affected versions, and patch status.

Known Records
45
High or Critical
6
Linked CVEs
43
Last Updated
Mar 25, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Elementor Website Builder – More Than Just a Page Builder so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
45 records include a published patch path.
Severity Mix
0 critical and 6 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Elementor Website Builder – More Than Just a Page Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-1206
Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template

The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats non-...

Published
Mar 25, 2026
Patched Release
3.35.8
Affected Versions
Versions up to 3.35.7
Next Step
Update to 3.35.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11220
Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path

The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all versions up to, and including, 3.33.3 due to insufficient neutralization of user-supplied input used to build SVG markup inside the widget. This makes it possi...

Published
Dec 15, 2025
Patched Release
3.33.4
Affected Versions
Versions up to 3.33.3
Next Step
Update to 3.33.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-67588
Elementor Website Builder <= 3.33.0 - Missing Authorization

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.33.0. This makes it possible for authenticated attackers, with Contribut...

Published
Nov 25, 2025
Patched Release
3.33.1
Affected Versions
Versions up to 3.33.0
Next Step
Update to 3.33.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-8081
Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import

The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administr...

Published
Aug 11, 2025
Patched Release
3.30.3
Affected Versions
Versions up to 3.30.2
Next Step
Update to 3.30.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4566
Elementor <= 3.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 due to insufficient input sanitization and outp...

Published
Jul 28, 2025
Patched Release
3.30.3
Affected Versions
Versions up to 3.30.2
Next Step
Update to 3.30.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3075
Elementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping o...

Published
Jul 28, 2025
Patched Release
3.29.1
Affected Versions
Versions up to 3.29.0
Next Step
Update to 3.29.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-54444
Elementor Website Builder <= 3.25.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.25.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...

Published
Feb 24, 2025
Patched Release
3.25.11
Affected Versions
Versions up to 3.25.10
Next Step
Update to 3.25.11 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13445
Elementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This...

Published
Feb 19, 2025
Patched Release
3.27.5
Affected Versions
Versions up to 3.27.4
Next Step
Update to 3.27.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10453
Elementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user sup...

Published
Dec 20, 2024
Patched Release
3.25.10
Affected Versions
Versions up to 3.25.9
Next Step
Update to 3.25.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-8236
Elementor Website Builder – More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This...

Published
Nov 25, 2024
Patched Release
3.25.8
Affected Versions
Versions up to 3.25.7
Next Step
Update to 3.25.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-6757
Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level a...

Published
Oct 14, 2024
Patched Release
3.24.6
Affected Versions
Versions up to 3.24.5
Next Step
Update to 3.24.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5416
Elementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on use...

Published
Sep 10, 2024
Patched Release
3.24.0
Affected Versions
Versions up to 3.23.4
Next Step
Update to 3.24.0 or newer if supported.