Elementor Website Builder Pro

Elementor Website Builder Pro has 17 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2026; all 17 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 9.9 out of 10. Severity breakdown: 2 critical and 2 high. 2024 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 10 of the records (59%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Missing Authorization.

Every one of the 17 issues recorded for Elementor Website Builder Pro has a vendor fix available, so running the current release closes all known holes.

11 independent researchers contributed these findings, most of them (6) reported by wesley (wcraft).

01234567891026.10.2018Today26.10.20186.1Elementor Pro <= 2.0.9 - Cross-Site Scripting CVSS 6.1 · 26.10.201806.05.20209.9Elementor Pro <= 2.9.3 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 9.9 · 06.05.202006.10.20207.2Elementor Pro <= 3.0.5 - Authenticated Remote Code Execution in Dynamic OOO Widget CVSS 7.2 · 06.10.202028.03.20238.8Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option CVSS 8.8 · 28.03.202320.06.20236.3Elementor Pro <= 3.13.0 - Missing Authorization CVSS 6.3 · 20.06.202326.02.20244.3Elementor Pro <= 3.19.2 - Authenticated (Contributor+) Information Exposure CVSS 4.3 · 26.02.202426.03.20246.4Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Widget SVGZ File Upload CVSS 6.4 · 26.03.20245.4Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation CVSS 5.4 · 26.03.20245.4Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 5.4 · 26.03.20246.4Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tag CVSS 6.4 · 26.03.20246.4Elementor Website Builder Pro <= 3.20.1 - Authententicated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 26.03.202402.05.20246.4Elementor Website Builder Pro <= 3.21.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CVSS 6.4 · 02.05.202428.06.20246.1Elementor Pro <= 3.21.2 - Reflected Cross-Site Scripting CVSS 6.1 · 28.06.202429.01.20254.3Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode CVSS 4.3 · 29.01.202509.06.20256.4Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 09.06.202519.06.20256.4Elementor Website Builder <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 19.06.202519.08.20269.8Elementor Pro <= 4.2.1 - Unauthenticated Arbitrary File Upload via Upload Field Array Validation Bypass CVSS 9.8 · 19.08.2026

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

17

Get automatic notifications for all Elementor Website Builder Pro vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.9CVE-2020-13126

Elementor Pro <= 2.9.3 - Authenticated (Subscriber+) Arbitrary File Upload

Read the full analysis

Vulnerability Records

17 records
2026-08-19 19:18CVE-2026-32475
9.8
Critical
Tin Pham (TF1T)Yes
2025-06-19 00:00CVE-2024-50555
6.4
Medium
BondsYes
2025-06-09 16:22CVE-2025-3076
6.4
Medium
TonnYes
2025-01-29 00:00CVE-2024-8494
4.3
Medium
Ankit PatelYes
2024-06-28 00:00CVE-2024-35656
6.1
Medium
MichaelYes
2024-05-02 00:00CVE-2024-4107
6.4
Medium
wesley (wcraft)Yes
2024-03-26 00:00CVE-2024-1521
6.4
Medium
wesley (wcraft)Yes
2024-03-26 00:00CVE-2024-2120
5.4
Medium
wesley (wcraft)Yes
2024-03-26 00:00CVE-2024-2121
5.4
Medium
wesley (wcraft)Yes
2024-03-26 00:00CVE-2024-2781
6.4
Medium
wesley (wcraft)Yes
Showing 1–10 of 17 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C