CVE · Medium

CVE-2026-6127 — Elementor Website Builder – more than just a page builder [elementor] < 4.0.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6127 Elementor Website Builder – more than just a page builder [elementor] < 4.0.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.0.5 4.0.5 2026-04-30

CVE-2026-6127

The Elementor Website Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through the _elementor_data meta field up to version 4.0.4. Insufficient input sanitization during form-encoded REST API requests allows attackers with contributor-level permissions or higher to inject malicious scripts that can be executed when users view affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.