PLUGIN SECURITY
Is Elementor Pro safe?
The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel perfect design, global and reusable style systems, mobile r …
What this plugin does
- Slug:
elementor-pro - Author: Elementor
- 10000000+ active installs
- 90/100 rating (7296 reviews on wordpress.org)
- 881766616 all-time downloads
- On WordPress.org since 2016-05-30
drag-and-dropeditorelementorlanding pagepage builder
Maintenance status
- Latest known version: 4.2.2
- Last updated: 2026-08-19 1:30pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
18 known CVEs on file for Elementor Pro.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-50555 | Elementor Pro [elementor-pro] < 3.29.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.29.1 | 3.29.1 | 2025-06-19 | ✓ fixed in latest |
| CVE-2026-32475 | Elementor Pro [elementor-pro] < 4.2.2 | Unrestricted Upload of File with Dangerous Type | Critical 9.0 | < 4.2.2 | 4.2.2 | 2025-06-19 | ✓ fixed in latest |
| CVE-2024-35656 | Elementor Pro [elementor-pro] < 3.21.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.21.3 | 3.21.3 | 2024-06-28 | ✓ fixed in latest |
| CVE-2024-4107 | Elementor Pro [elementor-pro] < 3.21.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.21.2 | 3.21.2 | 2024-05-02 | ✓ fixed in latest |
| CVE-2024-2121 | Elementor Pro [elementor-pro] < 3.20.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.20.2 | 3.20.2 | 2024-03-26 | ✓ fixed in latest |
| CVE-2024-2120 | Elementor Pro [elementor-pro] < 3.20.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.20.2 | 3.20.2 | 2024-03-26 | ✓ fixed in latest |
| CVE-2024-2781 | Elementor Pro [elementor-pro] < 3.20.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.20.2 | 3.20.2 | 2024-03-26 | ✓ fixed in latest |
| CVE-2024-1364 | Elementor Pro [elementor-pro] < 3.20.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.20.2 | 3.20.2 | 2024-03-26 | ✓ fixed in latest |
+ 14 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-1521 | Elementor Pro [elementor-pro] < 3.20.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.20.2 | 3.20.2 | 2024-03-26 | ✓ fixed in latest |
| CVE-2024-23523 | Elementor Pro [elementor-pro] < 3.19.3 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 6.5 | < 3.19.3 | 3.19.3 | 2024-02-26 | ✓ fixed in latest |
| CVE-2023-35050 | Elementor Pro [elementor-pro] < 3.13.1 | Missing Authorization | Medium 5.4 | < 3.13.1 | 3.13.1 | 2023-06-20 | ✓ fixed in latest |
| CVE-2023-3124 | Elementor Pro [elementor-pro] < 3.11.7 | Missing Authorization | High 8.8 | < 3.11.7 | 3.11.7 | 2023-03-28 | ✓ fixed in latest |
| — | Elementor Pro [elementor-pro] < 3.11.7 | — | Unknown | < 3.11.7 | 3.11.7 | 2023-03-28 | ✓ fixed in latest |
| CVE-2020-26596 | Elementor Pro [elementor-pro] < 3.0.6 | Improper Privilege Management | High 8.8 | < 3.0.6 | 3.0.6 | 2020-10-06 | ✓ fixed in latest |
| CVE-2020-13125 | Elementor Pro [elementor-pro] < 2.9.4 | — | Medium 6.5 | < 2.9.4 | 2.9.4 | 2020-05-17 | ✓ fixed in latest |
| CVE-2020-13126 | Elementor Pro [elementor-pro] < 2.9.4 | Unrestricted Upload of File with Dangerous Type | Critical 9.9 | < 2.9.4 | 2.9.4 | 2020-05-06 | ✓ fixed in latest |
| CVE-2018-18379 | Elementor Pro [elementor-pro] < 2.0.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.0.10 | 2.0.10 | 2018-10-26 | ✓ fixed in latest |
| — | Elementor Pro [elementor-pro] < 3.25.11 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 6.5 | < 3.25.11 | 3.25.11 | 0000-00-00 | ✓ fixed in latest |
| — | Elementor Pro [elementor-pro] < 3.29.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.29.1 | 3.29.1 | 0000-00-00 | ✓ fixed in latest |
| CVE-2023-3124 | Elementor Pro < 3.11.7 - Subscriber+ Arbitrary Options Update | — | Unknown | < 3.11.7 | 3.11.7 | — | ✓ fixed in latest |
| CVE-2024-8494 | Elementor Website Builder Pro – More than Just a Page Builder < 3.25.11 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode | — | Unknown | < 3.25.11 | 3.25.11 | — | ✓ fixed in latest |
| CVE-2025-3076 | Elementor Pro < 3.29.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 3.29.1 | 3.29.1 | — | ✓ fixed in latest |
How to fix it
Keep Elementor Pro updated — 4.2.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Classic Editor — 9000000+ active installs — 98/100 (1246) — max PHP 8.4
- Classic Widgets — 2000000+ active installs — 98/100 (272) — max PHP 8.4
- Advanced Editor Tools — 1000000+ active installs — 90/100 (354) — max PHP 8.4
- Spectra Legacy – Gutenberg Blocks — 1000000+ active installs — 94/100 (1870) — max PHP 8.4
- User Role Editor — 700000+ active installs — 90/100 (288) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.