SecAlerts
e

elementor

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 98 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 10, 2019 to present

98
Total CVEs
16
Critical+High
4
Exploited
10
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
10
Critical/High
Risk Level
42/100
medium
⚠️ 4 Active Exploits🆕 1Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
7
High
9
Medium
78
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
16

Age Distribution

Common Weaknesses (CWE)

1
XSS
61
2
Infoleak
6
3
Malicious File Upload
5
4
Path Traversal
3
5
CSRF
1

Most Affected Products

1. Elementor Website Builder WordPress38
2. Elementor Website Builder13
3. Elementor Elementor Page Builder Wordpress8
4. Elementor Elementor Website Builder7
5. Elementor Elementor Pro Wordpress7

Recent Vulnerabilities

See more →
CVE-2026-90953
CVSS 4.3medium

Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks

Sep 30, 2026🔧 No Patch
CVE-2026-62062
CVSS 8.8high

WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability

Sep 25, 2026🔧 No Patch
CVE-2026-77150
CVSS 6.1medium

Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting

Sep 11, 2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1w9q1cx/elementor_pro_wordpress_plugin_vulnerability/
unknown

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Sep 7, 2026🔧 No Patch
bleepingcomputer-20260903145220
unknown

Critical Elementor Pro flaw exploited to take over WordPress sites

Sep 3, 2026⚠ Exploited🔧 No Patch
bleepingcomputer-20260820143948
unknown

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

Aug 20, 2026⚠ Exploited🔧 No Patch
CVE-2026-32475
CVSS 9.0critical

WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability

Aug 19, 2026🔧 No Patch
CVE-2026-14230
CVSS 5.4medium

ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings

Aug 15, 2026🔧 No Patch
CVE-2026-15787
CVSS 6.4medium

Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes

Jul 22, 2026🔧 No Patch
CVE-2026-8825
CVSS 4.9EPSS 0%medium

Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API

Jul 20, 2026🔧 No Patch

Monitor elementor in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

elementor Security Vulnerabilities & Risk Score | 98 CVEs | SecAlerts - SecAlerts