Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Elementor Website Builder — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in Elementor Website Builder, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the Elementor Website Builder, a widely used WordPress plugin developed by Elementor Ltd. It focuses on weaknesses that arise from improper security measures, input validation errors, or access control flaws within the software ecosystem. The content aggregates data regarding these issues, covering the period from the software’s major public releases through to the most recent updates, ensuring a comprehensive view of historical and ongoing security concerns. Visitors to this page can track advisories issued by the vendor, gaining insight into how quickly specific flaws are identified and patched. Users may also explore specific weakness classes to understand the underlying technical causes, such as cross-site scripting or remote code execution, that frequently impact this type of web builder. Furthermore, the resource serves as a lookup tool for the product’s vulnerability history, allowing security professionals and site administrators to review past incidents and assess the cumulative risk profile of the platform over time. This structured approach helps stakeholders make informed decisions about security configurations and update schedules. By consolidating disparate reports and vendor notifications into a single reference point, the page facilitates a clearer understanding of the threat landscape surrounding Elementor. It is designed for developers, security analysts, and site owners who require accurate, verified information to maintain the integrity of their WordPress-based websites against known exploits.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-8825 Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API --2026-07-20
CVE-2026-57619 WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure vulnerability CWE-862 6.5 Medium2026-06-25
CVE-2026-49782 WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerability CWE-862 5.4 Medium2026-06-02
CVE-2026-32445 WordPress Elementor Website Builder plugin <= 3.35.5 - Broken Access Control vulnerability CWE-862 2.7 Low2026-03-13
CVE-2026-32352 WordPress Elementor Website Builder plugin <= 3.35.5 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-03-13
CVE-2024-50555 WordPress Elementor Website Builder plugin <= 3.29.0 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-02-20
CVE-2025-67588 WordPress Elementor Website Builder plugin <= 3.33.0 - Broken Access Control vulnerability CWE-862 4.3 Medium2025-12-09
CVE-2024-54444 WordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-02-25
CVE-2024-37437 WordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerability CWE-79 5.5 Medium2024-07-09
CVE-2023-33922 WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability CWE-862 4.3 Medium2024-06-11
CVE-2024-24934 WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability CWE-22 8.5 High2024-05-17
CVE-2023-47504 WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability CWE-287 6.5 Medium2024-04-24
CVE-2023-48777 WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability CWE-434 9.9 Critical2024-03-26
CVE-2022-4953 Elementor < 3.5.5 - Iframe Injection 6.1 -2023-08-14
CVE-2023-0329 Elementor Website Builder < 3.12.2 - Admin+ SQLi 7.2 -2023-05-30
CVE-2021-24891 Elementor < 3.4.8 - DOM Cross-Site-Scripting CWE-79 6.1 -2021-11-23
CVE-2021-24201 Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element CWE-79 5.4 -2021-04-05
CVE-2021-24206 Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget CWE-79 5.4 -2021-04-05
CVE-2021-24205 Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget CWE-79 5.4 -2021-04-05
CVE-2021-24204 Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget CWE-79 5.4 -2021-04-05
CVE-2021-24203 Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget CWE-79 5.4 -2021-04-05
CVE-2021-24202 Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget CWE-79 5.4 -2021-04-05

All 22 known CVE vulnerabilities affecting Elementor Website Builder with full Chinese analysis, references, and POCs where available.