PLUGIN SECURITY

Is Elementor safe?

The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel perfect design, global and reusable style systems, mobile r …

What this plugin does

  • Slug: elementor
  • Author: Elementor
  • 10000000+ active installs
  • 90/100 rating (7296 reviews on wordpress.org)
  • 881766616 all-time downloads
  • On WordPress.org since 2016-05-30

drag-and-dropeditorelementorlanding pagepage builder

Maintenance status

  • Latest known version: 4.2.2
  • Last updated: 2026-08-19 1:30pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

51 known CVEs on file for Elementor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8825 Elementor Website Builder – more than just a page builder [elementor] < 4.1.4 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 4.1.4 4.1.4 2026-06-29 ✓ fixed in latest
CVE-2026-57619 Elementor Website Builder – more than just a page builder [elementor] < 4.1.4 Missing Authorization Medium 6.5 < 4.1.4 4.1.4 2026-06-25 ✓ fixed in latest
CVE-2026-49782 Elementor Website Builder – more than just a page builder [elementor] < 4.1.1 Missing Authorization Medium 5.4 < 4.1.1 4.1.1 2026-06-02 ✓ fixed in latest
CVE-2026-6127 Elementor Website Builder – more than just a page builder [elementor] < 4.0.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.0.5 4.0.5 2026-04-30 ✓ fixed in latest
CVE-2025-14732 Elementor Website Builder – more than just a page builder [elementor] < 3.35.6 Improper Neutralization of Alternate XSS Syntax Medium 6.4 < 3.35.6 3.35.6 2026-04-07 ✓ fixed in latest
CVE-2026-32445 Elementor Website Builder – more than just a page builder [elementor] < 3.35.6 Missing Authorization Low 2.7 < 3.35.6 3.35.6 2026-03-07 ✓ fixed in latest
CVE-2026-32352 Elementor Website Builder – more than just a page builder [elementor] < 3.35.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.35.6 3.35.6 2026-02-13 ✓ fixed in latest
CVE-2025-11220 Elementor Website Builder – more than just a page builder [elementor] < 3.33.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.33.4 3.33.4 2025-12-15 ✓ fixed in latest
+ 62 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-67588 Elementor Website Builder – more than just a page builder [elementor] < 3.33.1 Missing Authorization Medium 4.3 < 3.33.1 3.33.1 2025-11-25 ✓ fixed in latest
CVE-2024-50555 Elementor Website Builder – more than just a page builder [elementor] < 3.29.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.29.1 3.29.1 2025-06-19 ✓ fixed in latest
CVE-2024-54444 Elementor Website Builder – more than just a page builder [elementor] < 3.25.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.25.11 3.25.11 2025-02-24 ✓ fixed in latest
CVE-2024-13445 Elementor Website Builder – more than just a page builder [elementor] < 3.27.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.27.5 3.27.5 2025-02-19 ✓ fixed in latest
CVE-2024-10453 Elementor Website Builder – more than just a page builder [elementor] < 3.25.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.25.10 3.25.10 2024-12-20 ✓ fixed in latest
CVE-2024-8236 Elementor Website Builder – more than just a page builder [elementor] < 3.25.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.25.8 3.25.8 2024-11-25 ✓ fixed in latest
CVE-2024-6757 Elementor Website Builder – more than just a page builder [elementor] < 3.24.6 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 3.24.6 3.24.6 2024-10-14 ✓ fixed in latest
CVE-2024-5416 Elementor Website Builder – more than just a page builder [elementor] < 3.24.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.24.0 3.24.0 2024-09-10 ✓ fixed in latest
CVE-2024-37437 Elementor Website Builder – more than just a page builder [elementor] < 3.22.2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 5.5 < 3.22.2 3.22.2 2024-06-28 ✓ fixed in latest
CVE-2024-4619 Elementor Website Builder – more than just a page builder [elementor] < 3.22.0-beta2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.22.0-beta2 3.22.0-beta2 2024-05-20 ✓ fixed in latest
CVE-2024-2117 Elementor Website Builder – more than just a page builder [elementor] < 3.20.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.20.3 3.20.3 2024-03-26 ✓ fixed in latest
CVE-2024-0506 Elementor Website Builder – more than just a page builder [elementor] < 3.19.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.19.0 3.19.0 2024-02-07 ✓ fixed in latest
CVE-2024-24934 Elementor Website Builder – more than just a page builder [elementor] < 3.19.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.5 < 3.19.1 3.19.1 2024-02-07 ✓ fixed in latest
CVE-2023-48777 Elementor Website Builder – more than just a page builder [elementor] < 3.18.2 Unrestricted Upload of File with Dangerous Type Critical 9.9 < 3.18.2 3.18.2 2023-12-06 ✓ fixed in latest
CVE-2023-47505 Elementor Website Builder – more than just a page builder [elementor] < 3.16.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.16.5 3.16.5 2023-11-08 ✓ fixed in latest
CVE-2023-47504 Elementor Website Builder – more than just a page builder [elementor] < 3.16.5 Improper Authentication Medium 6.5 < 3.16.5 3.16.5 2023-11-08 ✓ fixed in latest
CVE-2022-4953 Elementor Website Builder – more than just a page builder [elementor] < 3.5.5 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 6.1 < 3.5.5 3.5.5 2023-07-19 ✓ fixed in latest
CVE-2023-33922 Elementor Website Builder – more than just a page builder [elementor] < 3.13.3 Missing Authorization Medium 4.3 < 3.13.3 3.13.3 2023-05-22 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.13.2 Unknown < 3.13.2 3.13.2 2023-05-12 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.13.2 Unknown < 3.13.2 3.13.2 2023-05-12 ✓ fixed in latest
CVE-2023-0329 Elementor Website Builder – more than just a page builder [elementor] < 3.12.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 3.12.2 3.12.2 2023-04-24 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.12.2 Unknown < 3.12.2 3.12.2 2023-04-24 ✓ fixed in latest
CVE-2022-29455 Elementor Website Builder – more than just a page builder [elementor] < 3.5.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.7 < 3.5.6 3.5.6 2022-06-13 ✓ fixed in latest
CVE-2022-1329 Elementor Website Builder – more than just a page builder [elementor] >= 3.6.0 - <= 3.6.2 Unrestricted Upload of File with Dangerous Type High 8.8 3.6.0–3.6.3 3.6.3 2022-04-13 ✓ fixed in latest
CVE-2021-24891 Elementor Website Builder – more than just a page builder [elementor] < 3.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.6.3 3.6.3 2021-03-23 ✓ fixed in latest
CVE-2021-24202 Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.4 3.1.4 2021-03-17 ✓ fixed in latest
CVE-2021-24203 Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.4 3.1.4 2021-03-17 ✓ fixed in latest
CVE-2021-24204 Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.4 3.1.4 2021-03-17 ✓ fixed in latest
CVE-2021-24205 Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.4 3.1.4 2021-03-17 ✓ fixed in latest
CVE-2021-24206 Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.4 3.1.4 2021-03-17 ✓ fixed in latest
CVE-2021-24201 Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.4 3.1.4 2021-03-17 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 Unknown < 3.1.4 3.1.4 2021-03-17 ✓ fixed in latest
CVE-2020-36171 Elementor Website Builder – more than just a page builder [elementor] < 3.0.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.0.14 3.0.14 2020-11-25 ✓ fixed in latest
CVE-2020-15020 Elementor Website Builder – more than just a page builder [elementor] < 2.9.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.14 2.9.14 2020-07-07 ✓ fixed in latest
CVE-2020-13864, CVE-2020-13865 Elementor Website Builder – more than just a page builder [elementor] < 2.9.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.10 2.9.10 2020-06-05 ✓ fixed in latest
CVE-2020-13865 Elementor Website Builder – more than just a page builder [elementor] < 2.9.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.10 2.9.10 2020-06-05 ✓ fixed in latest
CVE-2020-36703 Elementor Website Builder – more than just a page builder [elementor] < 2.9.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.9.8 2.9.8 2020-04-21 ✓ fixed in latest
CVE-2020-20634 Elementor Website Builder – more than just a page builder [elementor] < 2.9.6 Medium 6.5 < 2.9.6 2.9.6 2020-03-31 ✓ fixed in latest
CVE-2020-20406 Elementor Website Builder – more than just a page builder [elementor] < 2.9.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.3 2.9.3 2020-02-26 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 2.7.6 Unknown < 2.7.6 2.7.6 2020-01-29 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 2.7.6 Unknown < 2.7.6 2.7.6 2020-01-29 ✓ fixed in latest
CVE-2020-8426 Elementor Website Builder – more than just a page builder [elementor] < 2.8.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.8.5 2.8.5 2020-01-28 ✓ fixed in latest
CVE-2020-7109 Elementor Website Builder – more than just a page builder [elementor] < 2.8.4 Critical 9.8 < 2.8.4 2.8.4 2020-01-19 ✓ fixed in latest
CVE-2020-7055 Elementor Website Builder – more than just a page builder [elementor] < 2.7.5 Unrestricted Upload of File with Dangerous Type Critical 9.9 < 2.7.5 2.7.5 2019-10-28 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 1.8.0 Unknown < 1.8.0 1.8.0 2017-12-02 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 1.8.8 Unknown < 1.8.8 1.8.8 2017-12-02 ✓ fixed in latest
CVE-2017-18596 Elementor Website Builder – more than just a page builder [elementor] < 1.8.0 Improper Privilege Management High 8.8 < 1.8.0 1.8.0 2017-11-27 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.30.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.30.3 3.30.3 0000-00-00 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.29.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.29.1 3.29.1 0000-00-00 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.30.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 3.30.3 3.30.3 0000-00-00 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.35.8 Unknown < 3.35.8 3.35.8 0000-00-00 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 2.9.8 Unknown < 2.9.8 2.9.8 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 2.7.7 Unknown < 2.7.7 2.7.7 ✓ fixed in latest
Elementor Website Builder – more than just a page builder [elementor] < 3.13.2 Unknown < 3.13.2 3.13.2 ✓ fixed in latest
Elementor Page Builder < 2.7.7 - Authenticated Stored XSS Unknown < 2.7.7 2.7.7 ✓ fixed in latest
CVE-2020-36703 Elementor < 2.9.8 - SVG Sanitizer Bypass leading to Authenticated Stored XSS Unknown < 2.9.8 2.9.8 ✓ fixed in latest
CVE-2023-0329 Elementor Website Builder < 3.12.2 - Admin+ SQLi Unknown < 3.12.2 3.12.2 ✓ fixed in latest
Elementor Website Builder < 3.13.2 - Missing Authorization Unknown < 3.13.2 3.13.2 ✓ fixed in latest
CVE-2025-3075 Elementor < 3.29.1 - Contributor+ Stored XSS Unknown < 3.29.1 3.29.1 ✓ fixed in latest
CVE-2025-4566 Elementor < 3.30.3 - Contributor+ Stored XSS via Text Path Widget Unknown < 3.30.3 3.30.3 ✓ fixed in latest
CVE-2025-8081 Elementor < 3.30.3 - Admin+ Arbitrary File Read via Image Import Unknown < 3.30.3 3.30.3 ✓ fixed in latest
CVE-2026-1206 Elementor Website Builder < 3.35.8 - Contributor+ Sensitive Information Exposure via Elementor Template Unknown < 3.35.8 3.35.8 ✓ fixed in latest

How to fix it

Keep Elementor updated — 4.2.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.