Known Vulnerabilities for Elementor Pro by Elementor
Listed below are 6 of the newest known vulnerabilities associated with "Elementor Pro" by "Elementor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-81777 json | Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-75971 json | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to ... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-74003 json | Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-73361 json | Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-66688 json | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-66609 json | Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-66438 json | Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-65549 json | Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-65534 json | Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65505 json | Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elementor | Elementor Pro | 3.0.5 |