CVE-2026-6127
Elementor Website Builder – more than just a page builder
Minimum safe version
4.0.5
Update to 4.0.5 or later to address 60 fixable vulnerabilities
CVE-2025-14732
Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template
CVE-2026-32352
CVE-2026-32445
CVE-2025-11220
CVE-2025-67588
Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import
Elementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Elementor <= 3.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget
CVE-2024-50555
CVE-2024-54444
CVE-2024-13445
WordPress Elementor Website Builder Plugin <= 3.25.9 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-8236
CVE-2024-6757
CVE-2024-5416
CVE-2024-37437
CVE-2024-4619
CVE-2024-2117
CVE-2024-24934
CVE-2024-0506
CVE-2023-48777
CVE-2023-47504
CVE-2023-47505
Elementor Website Builder < 3.13.2 - Missing Authorization
CVE-2022-4953
CVE-2020-36703
CVE-2023-0329
CVE-2023-33922
WordPress Elementor Website Builder Plugin <= 3.13.1 is vulnerable to Broken Access Control
Elementor <= 3.13.1 - Missing Authorization to Settings Update
WordPress Elementor Website Builder Plugin <= 3.12.1 is vulnerable to SQL Injection
Elementor <= 3.12.1 - Authenticated(Administrator+) SQL Injection via 'replace_urls'
Elementor Page Builder < 2.7.6 - Authenticated Stored XSS
Elementor < 2.9.8 - SVG Sanitizer Bypass leading to Authenticated Stored XSS
CVE-2020-7055
Elementor Website Builder <= 2.7.5 - Stored Cross-Site Scripting
Elementor Website Builder <= 2.9.7 - Authenticated Stored Cross-Site Scripting
CVE-2022-29455
WordPress Elementor Page Builder <=1.8.7 - Potential Privilege Escalation vulnerability
WordPress Elementor Page Builder <=1.7.12 - Authenticated Unrestricted Editing vulnerability
WordPress Elementor Page Builder plugin <= 2.7.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Elementor Website Builder plugin <= 3.1.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2022-1329
CVE-2017-18596
CVE-2020-7109
WordPress Elementor Page Builder plugin <= 2.8.4 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2020-13865
CVE-2020-13864
CVE-2020-20634
WordPress Elementor Website Builder plugin <= 2.9.13 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2020-20406
CVE-2020-36171
CVE-2021-24201
CVE-2021-24206
CVE-2021-24205
CVE-2021-24204
CVE-2021-24203
CVE-2021-24202
CVE-2021-24891