PLUGIN SECURITY
Is Elementor safe?
The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel perfect design, global and reusable style systems, mobile r …
What this plugin does
- Slug:
elementor - Author: Elementor
- 10000000+ active installs
- 90/100 rating (7296 reviews on wordpress.org)
- 881766616 all-time downloads
- On WordPress.org since 2016-05-30
drag-and-dropeditorelementorlanding pagepage builder
Maintenance status
- Latest known version: 4.2.2
- Last updated: 2026-08-19 1:30pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
51 known CVEs on file for Elementor.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-8825 | Elementor Website Builder – more than just a page builder [elementor] < 4.1.4 | Exposure of Sensitive Information to an Unauthorized Actor | Unknown | < 4.1.4 | 4.1.4 | 2026-06-29 | ✓ fixed in latest |
| CVE-2026-57619 | Elementor Website Builder – more than just a page builder [elementor] < 4.1.4 | Missing Authorization | Medium 6.5 | < 4.1.4 | 4.1.4 | 2026-06-25 | ✓ fixed in latest |
| CVE-2026-49782 | Elementor Website Builder – more than just a page builder [elementor] < 4.1.1 | Missing Authorization | Medium 5.4 | < 4.1.1 | 4.1.1 | 2026-06-02 | ✓ fixed in latest |
| CVE-2026-6127 | Elementor Website Builder – more than just a page builder [elementor] < 4.0.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 4.0.5 | 4.0.5 | 2026-04-30 | ✓ fixed in latest |
| CVE-2025-14732 | Elementor Website Builder – more than just a page builder [elementor] < 3.35.6 | Improper Neutralization of Alternate XSS Syntax | Medium 6.4 | < 3.35.6 | 3.35.6 | 2026-04-07 | ✓ fixed in latest |
| CVE-2026-32445 | Elementor Website Builder – more than just a page builder [elementor] < 3.35.6 | Missing Authorization | Low 2.7 | < 3.35.6 | 3.35.6 | 2026-03-07 | ✓ fixed in latest |
| CVE-2026-32352 | Elementor Website Builder – more than just a page builder [elementor] < 3.35.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.35.6 | 3.35.6 | 2026-02-13 | ✓ fixed in latest |
| CVE-2025-11220 | Elementor Website Builder – more than just a page builder [elementor] < 3.33.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.33.4 | 3.33.4 | 2025-12-15 | ✓ fixed in latest |
+ 62 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-67588 | Elementor Website Builder – more than just a page builder [elementor] < 3.33.1 | Missing Authorization | Medium 4.3 | < 3.33.1 | 3.33.1 | 2025-11-25 | ✓ fixed in latest |
| CVE-2024-50555 | Elementor Website Builder – more than just a page builder [elementor] < 3.29.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.29.1 | 3.29.1 | 2025-06-19 | ✓ fixed in latest |
| CVE-2024-54444 | Elementor Website Builder – more than just a page builder [elementor] < 3.25.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.25.11 | 3.25.11 | 2025-02-24 | ✓ fixed in latest |
| CVE-2024-13445 | Elementor Website Builder – more than just a page builder [elementor] < 3.27.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.27.5 | 3.27.5 | 2025-02-19 | ✓ fixed in latest |
| CVE-2024-10453 | Elementor Website Builder – more than just a page builder [elementor] < 3.25.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.25.10 | 3.25.10 | 2024-12-20 | ✓ fixed in latest |
| CVE-2024-8236 | Elementor Website Builder – more than just a page builder [elementor] < 3.25.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.25.8 | 3.25.8 | 2024-11-25 | ✓ fixed in latest |
| CVE-2024-6757 | Elementor Website Builder – more than just a page builder [elementor] < 3.24.6 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 4.3 | < 3.24.6 | 3.24.6 | 2024-10-14 | ✓ fixed in latest |
| CVE-2024-5416 | Elementor Website Builder – more than just a page builder [elementor] < 3.24.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.24.0 | 3.24.0 | 2024-09-10 | ✓ fixed in latest |
| CVE-2024-37437 | Elementor Website Builder – more than just a page builder [elementor] < 3.22.2 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 5.5 | < 3.22.2 | 3.22.2 | 2024-06-28 | ✓ fixed in latest |
| CVE-2024-4619 | Elementor Website Builder – more than just a page builder [elementor] < 3.22.0-beta2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.22.0-beta2 | 3.22.0-beta2 | 2024-05-20 | ✓ fixed in latest |
| CVE-2024-2117 | Elementor Website Builder – more than just a page builder [elementor] < 3.20.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.20.3 | 3.20.3 | 2024-03-26 | ✓ fixed in latest |
| CVE-2024-0506 | Elementor Website Builder – more than just a page builder [elementor] < 3.19.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.19.0 | 3.19.0 | 2024-02-07 | ✓ fixed in latest |
| CVE-2024-24934 | Elementor Website Builder – more than just a page builder [elementor] < 3.19.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.5 | < 3.19.1 | 3.19.1 | 2024-02-07 | ✓ fixed in latest |
| CVE-2023-48777 | Elementor Website Builder – more than just a page builder [elementor] < 3.18.2 | Unrestricted Upload of File with Dangerous Type | Critical 9.9 | < 3.18.2 | 3.18.2 | 2023-12-06 | ✓ fixed in latest |
| CVE-2023-47505 | Elementor Website Builder – more than just a page builder [elementor] < 3.16.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.16.5 | 3.16.5 | 2023-11-08 | ✓ fixed in latest |
| CVE-2023-47504 | Elementor Website Builder – more than just a page builder [elementor] < 3.16.5 | Improper Authentication | Medium 6.5 | < 3.16.5 | 3.16.5 | 2023-11-08 | ✓ fixed in latest |
| CVE-2022-4953 | Elementor Website Builder – more than just a page builder [elementor] < 3.5.5 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 6.1 | < 3.5.5 | 3.5.5 | 2023-07-19 | ✓ fixed in latest |
| CVE-2023-33922 | Elementor Website Builder – more than just a page builder [elementor] < 3.13.3 | Missing Authorization | Medium 4.3 | < 3.13.3 | 3.13.3 | 2023-05-22 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.13.2 | — | Unknown | < 3.13.2 | 3.13.2 | 2023-05-12 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.13.2 | — | Unknown | < 3.13.2 | 3.13.2 | 2023-05-12 | ✓ fixed in latest |
| CVE-2023-0329 | Elementor Website Builder – more than just a page builder [elementor] < 3.12.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 3.12.2 | 3.12.2 | 2023-04-24 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.12.2 | — | Unknown | < 3.12.2 | 3.12.2 | 2023-04-24 | ✓ fixed in latest |
| CVE-2022-29455 | Elementor Website Builder – more than just a page builder [elementor] < 3.5.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.7 | < 3.5.6 | 3.5.6 | 2022-06-13 | ✓ fixed in latest |
| CVE-2022-1329 | Elementor Website Builder – more than just a page builder [elementor] >= 3.6.0 - <= 3.6.2 | Unrestricted Upload of File with Dangerous Type | High 8.8 | 3.6.0–3.6.3 | 3.6.3 | 2022-04-13 | ✓ fixed in latest |
| CVE-2021-24891 | Elementor Website Builder – more than just a page builder [elementor] < 3.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.6.3 | 3.6.3 | 2021-03-23 | ✓ fixed in latest |
| CVE-2021-24202 | Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.1.4 | 3.1.4 | 2021-03-17 | ✓ fixed in latest |
| CVE-2021-24203 | Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.1.4 | 3.1.4 | 2021-03-17 | ✓ fixed in latest |
| CVE-2021-24204 | Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.1.4 | 3.1.4 | 2021-03-17 | ✓ fixed in latest |
| CVE-2021-24205 | Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.1.4 | 3.1.4 | 2021-03-17 | ✓ fixed in latest |
| CVE-2021-24206 | Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.1.4 | 3.1.4 | 2021-03-17 | ✓ fixed in latest |
| CVE-2021-24201 | Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.1.4 | 3.1.4 | 2021-03-17 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.1.4 | — | Unknown | < 3.1.4 | 3.1.4 | 2021-03-17 | ✓ fixed in latest |
| CVE-2020-36171 | Elementor Website Builder – more than just a page builder [elementor] < 3.0.14 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.0.14 | 3.0.14 | 2020-11-25 | ✓ fixed in latest |
| CVE-2020-15020 | Elementor Website Builder – more than just a page builder [elementor] < 2.9.14 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.9.14 | 2.9.14 | 2020-07-07 | ✓ fixed in latest |
| CVE-2020-13864, CVE-2020-13865 | Elementor Website Builder – more than just a page builder [elementor] < 2.9.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.9.10 | 2.9.10 | 2020-06-05 | ✓ fixed in latest |
| CVE-2020-13865 | Elementor Website Builder – more than just a page builder [elementor] < 2.9.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.9.10 | 2.9.10 | 2020-06-05 | ✓ fixed in latest |
| CVE-2020-36703 | Elementor Website Builder – more than just a page builder [elementor] < 2.9.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.9.8 | 2.9.8 | 2020-04-21 | ✓ fixed in latest |
| CVE-2020-20634 | Elementor Website Builder – more than just a page builder [elementor] < 2.9.6 | — | Medium 6.5 | < 2.9.6 | 2.9.6 | 2020-03-31 | ✓ fixed in latest |
| CVE-2020-20406 | Elementor Website Builder – more than just a page builder [elementor] < 2.9.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.9.3 | 2.9.3 | 2020-02-26 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 2.7.6 | — | Unknown | < 2.7.6 | 2.7.6 | 2020-01-29 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 2.7.6 | — | Unknown | < 2.7.6 | 2.7.6 | 2020-01-29 | ✓ fixed in latest |
| CVE-2020-8426 | Elementor Website Builder – more than just a page builder [elementor] < 2.8.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.8.5 | 2.8.5 | 2020-01-28 | ✓ fixed in latest |
| CVE-2020-7109 | Elementor Website Builder – more than just a page builder [elementor] < 2.8.4 | — | Critical 9.8 | < 2.8.4 | 2.8.4 | 2020-01-19 | ✓ fixed in latest |
| CVE-2020-7055 | Elementor Website Builder – more than just a page builder [elementor] < 2.7.5 | Unrestricted Upload of File with Dangerous Type | Critical 9.9 | < 2.7.5 | 2.7.5 | 2019-10-28 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 1.8.0 | — | Unknown | < 1.8.0 | 1.8.0 | 2017-12-02 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 1.8.8 | — | Unknown | < 1.8.8 | 1.8.8 | 2017-12-02 | ✓ fixed in latest |
| CVE-2017-18596 | Elementor Website Builder – more than just a page builder [elementor] < 1.8.0 | Improper Privilege Management | High 8.8 | < 1.8.0 | 1.8.0 | 2017-11-27 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.30.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.30.3 | 3.30.3 | 0000-00-00 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.29.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.29.1 | 3.29.1 | 0000-00-00 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.30.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 4.9 | < 3.30.3 | 3.30.3 | 0000-00-00 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.35.8 | — | Unknown | < 3.35.8 | 3.35.8 | 0000-00-00 | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 2.9.8 | — | Unknown | < 2.9.8 | 2.9.8 | — | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 2.7.7 | — | Unknown | < 2.7.7 | 2.7.7 | — | ✓ fixed in latest |
| — | Elementor Website Builder – more than just a page builder [elementor] < 3.13.2 | — | Unknown | < 3.13.2 | 3.13.2 | — | ✓ fixed in latest |
| — | Elementor Page Builder < 2.7.7 - Authenticated Stored XSS | — | Unknown | < 2.7.7 | 2.7.7 | — | ✓ fixed in latest |
| CVE-2020-36703 | Elementor < 2.9.8 - SVG Sanitizer Bypass leading to Authenticated Stored XSS | — | Unknown | < 2.9.8 | 2.9.8 | — | ✓ fixed in latest |
| CVE-2023-0329 | Elementor Website Builder < 3.12.2 - Admin+ SQLi | — | Unknown | < 3.12.2 | 3.12.2 | — | ✓ fixed in latest |
| — | Elementor Website Builder < 3.13.2 - Missing Authorization | — | Unknown | < 3.13.2 | 3.13.2 | — | ✓ fixed in latest |
| CVE-2025-3075 | Elementor < 3.29.1 - Contributor+ Stored XSS | — | Unknown | < 3.29.1 | 3.29.1 | — | ✓ fixed in latest |
| CVE-2025-4566 | Elementor < 3.30.3 - Contributor+ Stored XSS via Text Path Widget | — | Unknown | < 3.30.3 | 3.30.3 | — | ✓ fixed in latest |
| CVE-2025-8081 | Elementor < 3.30.3 - Admin+ Arbitrary File Read via Image Import | — | Unknown | < 3.30.3 | 3.30.3 | — | ✓ fixed in latest |
| CVE-2026-1206 | Elementor Website Builder < 3.35.8 - Contributor+ Sensitive Information Exposure via Elementor Template | — | Unknown | < 3.35.8 | 3.35.8 | — | ✓ fixed in latest |
How to fix it
Keep Elementor updated — 4.2.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Classic Editor — 9000000+ active installs — 98/100 (1246) — max PHP 8.4
- Classic Widgets — 2000000+ active installs — 98/100 (272) — max PHP 8.4
- Advanced Editor Tools — 1000000+ active installs — 90/100 (354) — max PHP 8.4
- Spectra Legacy – Gutenberg Blocks — 1000000+ active installs — 94/100 (1870) — max PHP 8.4
- User Role Editor — 700000+ active installs — 90/100 (288) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.