Known Vulnerabilities for Elementor Pro by Elementor
Listed below are 6 of the newest known vulnerabilities associated with "Elementor Pro" by "Elementor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49782 json | Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Co... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-49765 json | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49109 json | Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja ... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49105 json | Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49104 json | Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable,... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49085 json | Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49053 json | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Acces... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-49052 json | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Acces... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-48870 json | Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-48837 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For ... | Not Provided | 2026-05-25 | 2026-05-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elementor | Elementor Pro | 3.0.5 |