Visibility Logic for Elementor

Visibility Logic for Elementor has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; all 4 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 4 issues recorded for Visibility Logic for Elementor has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Visibility Logic for Elementor is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Visibility Logic for Elementor vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3

Visibility Logic for Elementor <= 2.3.4 - Missing Authorization via admin_post 'toggle_option'

Read the full analysis

Vulnerability Records

4 records
Visibility Logic for Elementor banner
Latestv2.5.1

Visibility Logic for Elementor

StaxWP

Author

StaxWP

4.8(58)
96/100
Last Updated
2026-09-08 (5d ago)
Active Installs
20,000+
Downloads
575,880
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2018-12-30 (8y ago)

Visibility Logic adds focused Display Conditions for Elementor to every widget, section, and container. Use conditional display rules to control exactly who sees what, when, and on which device without writing a single line of code. By default, hidden elements are removed from the HTML instead of only hidden with CSS. If you need the markup to stay in the DOM, enable the Keep HTML / Hide by CSS option. When to use Visibility Logic Restrict content to logged-in users, specific roles, or subscribers Control membership content with Elementor sections for members, subscribers, guests, or specific roles Schedule content to appear during a sale, event, or launch window Personalize pages based on user meta, ACF custom fields, or device type Show/hide Elementor elements for Desktop, Tablet, or Mobile visitors A/B test layouts by showing different content to different user segments Hide empty sections automatically when all child widgets are hidden Free Conditions ACF Fields (NEW): Show/hide based on Advanced Custom Fields values on the current post or page. 7 operators: is empty, is not empty, equals, not equals, contains, is true, is false. Device Type (NEW): Target Desktop, Tablet, or Mobile users with server-side User-Agent detection. Hidden elements are fully removed from HTML. User Role: Logged in, logged out, or specific roles (Administrator, Editor, Subscriber, custom roles). User Meta: Show/hide based on any user meta field value. Date & Time: Schedule visibility with “from” and “to” dates. Perfect for sales, events, and time-limited content. Browser Type: Target Chrome, Firefox, Safari, Edge, Opera, iPhone, Android, and more. Flexbox Containers: Full support for Elementor’s Flexbox containers, classic sections, and nested containers. Hide When Empty: Automatically hide a parent section/container when all child widgets are hidden by visibility conditions. PRO Conditions Advanced ACF: Repeater fields, options page, term meta, user fields, specific post/user sources, AND/OR logic with 17 operators. Language: Show/hide based on current language. Supports WPML, Polylang, and TranslatePress. URL Parameters: URL parameter visibility and standalone query string conditions with repeater support and 9 operators. Geo Location: Display elements based on visitor’s country using MaxMind geolocation. Dynamic Conditions: Use all Elementor Pro Dynamic Tags as visibility conditions. WooCommerce: Restrict content based on order history, active subscriptions, or customer status. Easy Digital Downloads: Restrict based on purchase history or subscription status. Advanced User Meta: Multiple user meta conditions with AND/OR logic. Post & Page, Taxonomy: Show/hide based on current post type, specific pages, or taxonomy terms. Archive: Conditions based on post type archives and taxonomy archives. IP & Referrer: Target visitors by IP address or referral source. WordPress Conditional Tags: Use any WordPress conditional tag as a visibility condition. Fallback Content: Replace hidden elements with a custom text message or an Elementor template. Copy/Paste: Right-click to copy visibility settings between widgets or sections. Get Visibility Logic Pro and unlock all conditions. How it works Edit any page with Elementor Select a widget, section, or container Go to the Visibility tab (or Advanced → Visibility Control) Enable conditions and configure your display rules Save: elements are shown or hidden on the live site based on your rules More from StaxWP BuddyBuilder: Build stunning BuddyPress communities with Elementor. Privacy Policy We use Appsero SDK to collect some telemetry data upon user’s confirmation. This helps us troubleshoot problems faster and make product improvements. Found a bug? Report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team helps validate, triage, and handle any security vulnerabilities. Credits This plugin implements some functionality similar to: * Dynamic Content for Elementor (GPL v2 or later)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C