Known Vulnerabilities for Elementor Pro by Elementor
Listed below are 1 of the newest known vulnerabilities associated with "Elementor Pro" by "Elementor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-32532 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Contact Form ... | Not Provided | 2026-03-25 | 2026-03-25 |
| CVE-2026-32527 | Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Fo... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-28135 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-add... | Not Provided | 2026-03-05 | 2026-04-01 |
| CVE-2026-25430 | Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Form... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-25398 | Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Exploitin... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-25007 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader Element... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-22518 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for E... | Not Provided | 2026-01-08 | 2026-04-01 |
| CVE-2026-3831 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data d... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-1206 | The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure... | Not Provided | 2026-03-26 | 2026-03-26 |
| CVE-2025-68560 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code... | Not Provided | 2025-12-23 | 2026-04-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elementor | Elementor Pro | 3.0.5 | All | All | All |