SecAlerts
e

elementor

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 93 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 10, 2019 to present

93
Total CVEs
15
Critical+High
3
Exploited
9
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
9
Critical/High
Risk Level
40/100
medium
⚠️ 3 Active Exploits🆕 2Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
7
High
8
Medium
76
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
16

Age Distribution

Common Weaknesses (CWE)

1
XSS
60
2
Malicious File Upload
5
3
Infoleak
5
4
Path Traversal
3
5
SQL Injection
1

Most Affected Products

1. Elementor Website Builder WordPress38
2. Elementor Website Builder13
3. Elementor Elementor Page Builder Wordpress8
4. Elementor Elementor Pro Wordpress7
5. Elementor Elementor Website Builder6

Recent Vulnerabilities

See more →
bleepingcomputer-20260820143948
unknown

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

Aug 20, 2026⚠ Exploited🔧 No Patch
CVE-2026-32475
CVSS 9.0critical

WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability

Aug 19, 2026🔧 No Patch
CVE-2026-14230
CVSS 5.4medium

ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings

Aug 15, 2026🔧 No Patch
CVE-2026-15787
CVSS 6.4medium

Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes

Jul 22, 2026🔧 No Patch
CVE-2026-8825
CVSS 4.9EPSS 0%medium

Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API

Jul 20, 2026🔧 No Patch
CVE-2026-15299
CVSS 6.4medium

Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget

Jul 10, 2026🔧 No Patch
CVE-2026-49782
CVSS 5.4medium

WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerability

Jun 2, 2026🔧 No Patch
CVE-2026-6127
CVSS 6.4EPSS 0%medium

Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

May 1, 2026🔧 No Patch
CVE-2025-14732
CVSS 6.4medium

Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

Apr 8, 2026🔧 No Patch
CVE-2026-1206
CVSS 4.3medium

Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template

Mar 26, 2026🔧 No Patch

Monitor elementor in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

elementor Security Vulnerabilities & Risk Score | 93 CVEs | SecAlerts - SecAlerts