Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Elementor — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting Elementor. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Elementor is a popular WordPress page builder enabling users to create custom websites through drag-and-drop functionality. Historically, it has been susceptible to multiple security vulnerabilities, including cross-site scripting (XSS), remote code execution (RCE), privilege escalation, and information disclosure. These vulnerabilities often stem from insufficient input validation and improper access controls. While no single major incident stands out, the 17 documented CVEs highlight consistent security challenges. The plugin's extensive user base makes it an attractive target for attackers, particularly when websites remain unpatched. Regular updates and proper configuration remain critical for mitigating risks associated with this widely used web development tool.

CVE ID Title CVSS Severity Published
CVE-2026-62062 WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability — Elementor Website Builder CWE-352 8.8 High 2026-09-25
CVE-2026-84759 WordPress Activity Log plugin <= 2.13.1 - Cross Site Request Forgery (CSRF) vulnerability — Activity Log CWE-352 7.1 High 2026-09-02
CVE-2026-32475 WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability — Elementor Pro CWE-434 9.0 Critical 2026-08-19
CVE-2026-57619 WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure vulnerability — Elementor Website Builder CWE-862 6.5 Medium 2026-06-25
CVE-2026-49782 WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerability — Elementor Website Builder CWE-862 5.4 Medium 2026-06-02
CVE-2026-32445 WordPress Elementor Website Builder plugin <= 3.35.5 - Broken Access Control vulnerability — Elementor Website Builder CWE-862 2.7 Low 2026-03-13
CVE-2026-32352 WordPress Elementor Website Builder plugin <= 3.35.5 - Cross Site Scripting (XSS) vulnerability — Elementor Website Builder CWE-79 6.5 Medium 2026-03-13
CVE-2024-50555 WordPress Elementor Website Builder plugin <= 3.29.0 - Cross Site Scripting (XSS) vulnerability — Elementor Website Builder CWE-79 6.5 Medium 2026-02-20
CVE-2026-25386 WordPress Ally plugin <= 4.0.2 - Broken Access Control vulnerability — Ally CWE-862 5.3 Medium 2026-02-19
CVE-2026-25387 WordPress Image Optimizer by Elementor plugin <= 1.7.1 - Broken Access Control vulnerability — Image Optimizer by Elementor CWE-862 4.3 Medium 2026-02-19
CVE-2025-67588 WordPress Elementor Website Builder plugin <= 3.33.0 - Broken Access Control vulnerability — Elementor Website Builder CWE-862 4.3 Medium 2025-12-09
CVE-2025-32640 WordPress One Click Accessibility plugin <= 3.1.0 - Cross-Site Scripting (XSS) vulnerability — Ally CWE-79 5.9 Medium 2025-04-09
CVE-2024-54444 WordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerability — Elementor Website Builder CWE-79 6.5 Medium 2025-02-25
CVE-2024-35656 WordPress Elementor Pro <= 3.21.2 - Reflected Cross Site Scripting (XSS) vulnerability — Elementor Pro CWE-79 7.1 High 2024-07-22
CVE-2024-37437 WordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerability — Elementor Website Builder CWE-79 5.5 Medium 2024-07-09
CVE-2023-35050 WordPress Elementor Pro plugin <= 3.13.0 - Auth. Broken Access Control vulnerability — Elementor Pro CWE-862 5.4 Medium 2024-06-19
CVE-2023-33922 WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability — Elementor Website Builder CWE-862 4.3 Medium 2024-06-11
CVE-2024-24934 WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability — Elementor Website Builder CWE-22 8.5 High 2024-05-17
CVE-2023-47504 WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability — Elementor Website Builder CWE-287 6.5 Medium 2024-04-24
CVE-2024-31289 WordPress Hello Elementor theme <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerability — Hello Elementor CWE-352 4.3 Medium 2024-04-12
CVE-2024-23523 WordPress Elementor Pro plugin <= 3.19.2 - Contributor+ Arbitrary User Meta Data Retrieval vulnerability — Elementor Pro CWE-200 6.5 Medium 2024-03-16
CVE-2022-29455 WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability — Elementor Website Builder (WordPress plugin) CWE-79 4.7 Medium 2022-06-13

This page lists every published CVE security advisory associated with Elementor. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.