Hello Elementor

Hello Elementor has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Hello Elementor has a vendor fix available, so running the current release closes it.

All of these findings were reported by Dhabaleshwar Das. Hello Elementor is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Hello Elementor vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2024-31289

Hello Elementor <= 3.0.0 - Cross-Site Request Forgery to Notice Dismissal

Read the full analysis

Vulnerability Records

1 records
Hello Elementor screenshot
Latestv3.5.1

Hello Elementor

Elementor

Author

Elementor

4.2(128)
84/100
Last Updated
2026-08-25 (19d ago)
Active Installs
1,000,000+
Downloads
15,453,938
Requires WP
6.0+
Requires PHP
7.4+
Created
2019-05-13 (7y ago)

Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work seamlessly with the Elementor site builder plugin. The theme is free, open-source, and designed for users who want a flexible, easy-to-use, and customizable website. The theme, which is optimized for performance, provides a solid foundation for users to build their own unique designs using the Elementor drag-and-drop site builder. Its simplicity and flexibility make it a great choice for both beginners and experienced Web Creators.

Tags
Custom logoCustom menuCustom colorsFeatured imagesFlexible headerThreaded commentsTranslation readyAccessibility readyRTL language support

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C