Hello Elementor
Hello Elementor has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Hello Elementor has a vendor fix available, so running the current release closes it.
All of these findings were reported by Dhabaleshwar Das. Hello Elementor is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-31289Hello Elementor <= 3.0.0 - Cross-Site Request Forgery to Notice Dismissal
Read the full analysisVulnerability Records

Hello Elementor
Author
Elementor
Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work seamlessly with the Elementor site builder plugin. The theme is free, open-source, and designed for users who want a flexible, easy-to-use, and customizable website. The theme, which is optimized for performance, provides a solid foundation for users to build their own unique designs using the Elementor drag-and-drop site builder. Its simplicity and flexibility make it a great choice for both beginners and experienced Web Creators.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C