SecAlerts
elementor logo

elementor

Security Risk Profile

33
/100
low

Security Risk Score

Comprehensive risk assessment based on 90 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 10, 2019 to present

90
Total CVEs
14
Critical+High
2
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
33/100
low
⚠️ 2 Active Exploits📈 3 in Last 30 Days

Severity Distribution

Critical
6
High
8
Medium
75
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
16

Age Distribution

Common Weaknesses (CWE)

1
XSS
59
2
Infoleak
5
3
Malicious File Upload
4
4
Path Traversal
3
5
SQL Injection
1

Most Affected Products

1. Elementor Website Builder WordPress38
2. Elementor Website Builder13
3. Elementor Elementor Page Builder Wordpress8
4. Elementor Elementor Pro Wordpress7
5. Elementor Elementor Website Builder6

Recent Vulnerabilities

See more →
CVE-2026-15787
CVSS 6.4medium

Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes

7/22/2026🔧 No Patch
CVE-2026-8825
CVSS 4.9EPSS 0%medium

Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API

7/20/2026🔧 No Patch
CVE-2026-15299
CVSS 6.4medium

Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget

7/10/2026🔧 No Patch
CVE-2026-49782
CVSS 5.4medium

WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerability

6/2/2026🔧 No Patch
CVE-2026-6127
CVSS 6.4EPSS 0%medium

Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

5/1/2026🔧 No Patch
CVE-2025-14732
CVSS 6.4medium

Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

4/8/2026🔧 No Patch
CVE-2026-1206
CVSS 4.3medium

Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template

3/26/2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/sqli-flaw-in-elementor-ally-plugin-impacts-250k-plus-wordpress-sites/
unknown

SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites

3/11/2026⚠ Exploited🔧 No Patch
CVE-2025-8666
CVSS 6.4medium

Testimonial Carousel For Elementor <= 11.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

10/25/2025🔧 No Patch
CVE-2025-8445
CVSS 6.4medium

Countdown Timer for Elementor <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'countdown_label'

9/11/2025🔧 No Patch

Monitor elementor in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

elementor Security Vulnerabilities & Risk Score | 90 CVEs | SecAlerts - SecAlerts