PLUGIN SECURITY

Is Elementor Pro safe?

The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel perfect design, global and reusable style systems, mobile r …

What this plugin does

  • Slug: elementor-pro
  • Author: Elementor
  • 10000000+ active installs
  • 90/100 rating (7296 reviews on wordpress.org)
  • 881766616 all-time downloads
  • On WordPress.org since 2016-05-30

drag-and-dropeditorelementorlanding pagepage builder

Maintenance status

  • Latest known version: 4.2.2
  • Last updated: 2026-08-19 1:30pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

18 known CVEs on file for Elementor Pro.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-50555 Elementor Pro [elementor-pro] < 3.29.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.29.1 3.29.1 2025-06-19 ✓ fixed in latest
CVE-2026-32475 Elementor Pro [elementor-pro] < 4.2.2 Unrestricted Upload of File with Dangerous Type Critical 9.0 < 4.2.2 4.2.2 2025-06-19 ✓ fixed in latest
CVE-2024-35656 Elementor Pro [elementor-pro] < 3.21.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.21.3 3.21.3 2024-06-28 ✓ fixed in latest
CVE-2024-4107 Elementor Pro [elementor-pro] < 3.21.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.21.2 3.21.2 2024-05-02 ✓ fixed in latest
CVE-2024-2121 Elementor Pro [elementor-pro] < 3.20.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.20.2 3.20.2 2024-03-26 ✓ fixed in latest
CVE-2024-2120 Elementor Pro [elementor-pro] < 3.20.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.20.2 3.20.2 2024-03-26 ✓ fixed in latest
CVE-2024-2781 Elementor Pro [elementor-pro] < 3.20.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.20.2 3.20.2 2024-03-26 ✓ fixed in latest
CVE-2024-1364 Elementor Pro [elementor-pro] < 3.20.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.20.2 3.20.2 2024-03-26 ✓ fixed in latest
+ 14 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1521 Elementor Pro [elementor-pro] < 3.20.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.20.2 3.20.2 2024-03-26 ✓ fixed in latest
CVE-2024-23523 Elementor Pro [elementor-pro] < 3.19.3 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 3.19.3 3.19.3 2024-02-26 ✓ fixed in latest
CVE-2023-35050 Elementor Pro [elementor-pro] < 3.13.1 Missing Authorization Medium 5.4 < 3.13.1 3.13.1 2023-06-20 ✓ fixed in latest
CVE-2023-3124 Elementor Pro [elementor-pro] < 3.11.7 Missing Authorization High 8.8 < 3.11.7 3.11.7 2023-03-28 ✓ fixed in latest
Elementor Pro [elementor-pro] < 3.11.7 Unknown < 3.11.7 3.11.7 2023-03-28 ✓ fixed in latest
CVE-2020-26596 Elementor Pro [elementor-pro] < 3.0.6 Improper Privilege Management High 8.8 < 3.0.6 3.0.6 2020-10-06 ✓ fixed in latest
CVE-2020-13125 Elementor Pro [elementor-pro] < 2.9.4 Medium 6.5 < 2.9.4 2.9.4 2020-05-17 ✓ fixed in latest
CVE-2020-13126 Elementor Pro [elementor-pro] < 2.9.4 Unrestricted Upload of File with Dangerous Type Critical 9.9 < 2.9.4 2.9.4 2020-05-06 ✓ fixed in latest
CVE-2018-18379 Elementor Pro [elementor-pro] < 2.0.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.0.10 2.0.10 2018-10-26 ✓ fixed in latest
Elementor Pro [elementor-pro] < 3.25.11 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 3.25.11 3.25.11 0000-00-00 ✓ fixed in latest
Elementor Pro [elementor-pro] < 3.29.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.29.1 3.29.1 0000-00-00 ✓ fixed in latest
CVE-2023-3124 Elementor Pro < 3.11.7 - Subscriber+ Arbitrary Options Update Unknown < 3.11.7 3.11.7 ✓ fixed in latest
CVE-2024-8494 Elementor Website Builder Pro – More than Just a Page Builder < 3.25.11 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode Unknown < 3.25.11 3.25.11 ✓ fixed in latest
CVE-2025-3076 Elementor Pro < 3.29.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Unknown < 3.29.1 3.29.1 ✓ fixed in latest

How to fix it

Keep Elementor Pro updated — 4.2.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.