Elementor Website Builder
by WordPress
Source repositories
CVEs (47)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-6757 | Med | 0.28 | 4.3 | 0.00 | Oct 15, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with… | ||
| CVE-2024-5416 | Med | 0.28 | 5.4 | 0.00 | Sep 11, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on… | ||
| CVE-2023-33922 | Med | 0.28 | 4.3 | 0.00 | Jun 11, 2024 | Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2. | ||
| CVE-2026-1206 | Med | 0.21 | 4.3 | 0.00 | Mar 26, 2026 | The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats… | ||
| CVE-2026-32445 | Low | 0.18 | 2.7 | 0.00 | Mar 13, 2026 | Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5. | ||
| CVE-2026-8825 | Med | 0.00 | 4.9 | 0.00 | Jul 20, 2026 | The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of… | ||
| CVE-2026-57619 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. |
- risk 0.28cvss 4.3epss 0.00
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with…
- risk 0.28cvss 5.4epss 0.00
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on…
- risk 0.28cvss 4.3epss 0.00
Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.
- risk 0.21cvss 4.3epss 0.00
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats…
- risk 0.18cvss 2.7epss 0.00
Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.
- risk 0.00cvss 4.9epss 0.00
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of…
- risk 0.00cvss 6.5epss 0.00
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
Page 3 of 3