Pricing
Case studies
Login
Start trial
Elementor Website Builder
Elementor
Developer
4.0.1
Latest version
10,000,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
36 patched
7 Mitigation rules
Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
<= 3.35.7
3 days ago
Broken Access Control vulnerability
<= 3.35.5
07/03/2026
Cross Site Scripting (XSS) vulnerability
<= 3.35.5
13/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 3.29.0
31/12/2025
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path vulnerability
<= 3.33.3
16/12/2025
Broken Access Control vulnerability
<= 3.33.0
25/11/2025
Authenticated (Administrator+) Arbitrary File Read via Image Import vulnerability
<= 3.30.2
11/08/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget vulnerability
<= 3.30.2
28/07/2025
Cross Site Scripting (XSS) vulnerability
<= 3.29.0
19/06/2025
Cross Site Scripting (XSS) vulnerability
<= 3.25.10
24/02/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 3.27.4
19/02/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings vulnerability
<= 3.25.9
23/12/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 3.25.7
26/11/2024
Authenticated (Contributor+) Basic Information Exposure via get_image_alt function vulnerability
<= 3.24.5
14/10/2024
Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets vulnerability
<= 3.23.4
11/09/2024
Arbitrary SVG File Download vulnerability
<= 3.22.1
28/06/2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
< 3.21.6
21/05/2024
Auth. Stored Cross-Site Scripting vulnerability
<= 3.20.2
26/03/2024
Authenticated Stored Cross-Site Scripting via get_image_alt vulnerability
<= 3.18.3
07/02/2024
Arbitrary File Deletion and Phar Deserialization vulnerability
<= 3.19.0
06/02/2024
Arbitrary File Upload vulnerability
3.3.0-3.18.1
06/12/2023
Contributor+ Arbitrary Attachment Read vulnerability
<= 3.16.4
08/11/2023
Contributor+ Cross Site Scripting (XSS) vulnerability
<= 3.16.4
08/11/2023
Broken Access Control vulnerability
<= 3.13.2
24/05/2023
Missing Authorization to Settings Update vulnerability
<= 3.13.1
12/05/2023
Admin+ SQLi
<= 3.12.1
24/04/2023
Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability
<= 3.5.5
13/06/2022
Arbitrary File Upload vulnerability
3.6.0-3.6.2
13/04/2022
DOM Cross-Site Scripting (XSS) vulnerability
<= 3.1.3
20/10/2021
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
<= 3.1.1
17/03/2021
Unrestricted SVG Uploads vulnerability
<= 3.0.13
25/11/2020
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.9.13
02/09/2020
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.8.4
30/01/2020
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.7.5
29/01/2020
Authenticated Unrestricted Editing vulnerability
<= 1.7.12
02/12/2017
Potential Privilege Escalation vulnerability
<= 1.8.7
02/12/2017