Known Vulnerabilities for products from Elementor

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Elementor".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-32532 Not Provided 2026-03-25 2026-03-25
CVE-2026-32527 Not Provided 2026-03-25 2026-03-26
CVE-2026-28135 Not Provided 2026-03-05 2026-04-01
CVE-2026-25430 Not Provided 2026-03-25 2026-03-26
CVE-2026-25398 Not Provided 2026-03-25 2026-03-26
CVE-2026-25007 Not Provided 2026-03-25 2026-03-26
CVE-2026-22518 Not Provided 2026-01-08 2026-04-01
CVE-2026-3831 Not Provided 2026-04-01 2026-04-01
CVE-2026-1206 Not Provided 2026-03-26 2026-03-26
CVE-2025-68560 Not Provided 2025-12-23 2026-04-01
CVE-2024-54444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Web... Not Provided 2025-02-25 2026-04-01
CVE-2024-37437 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Web... Not Provided 2024-07-09 2026-04-01
CVE-2021-24891 The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a ... 6.1 - MEDIUM 2021-11-23 2021-12-15
CVE-2021-24206 In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts... 5.4 - MEDIUM 2021-04-05 2021-04-09
CVE-2021-24205 In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a... 5.4 - MEDIUM 2021-04-05 2021-04-09
CVE-2021-24204 In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts... 5.4 - MEDIUM 2021-04-05 2021-04-09
CVE-2021-24203 In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ... 5.4 - MEDIUM 2021-04-05 2021-04-09
CVE-2021-24202 In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a �... 5.4 - MEDIUM 2021-04-05 2021-04-09
CVE-2021-24201 In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ... 5.4 - MEDIUM 2021-04-05 2023-11-07
CVE-2020-36171 The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads. 6.1 - MEDIUM 2021-01-06 2021-01-11

Known software with vulnerabilities from Elementor

Type Vendor Product Version
ApplicationElementorElementor-
ApplicationElementorElementor Page Builder-
ApplicationElementorElementor Pro3.0.5
ApplicationElementorPage Builder2.9.0
ApplicationElementorWebsite Builder-