CVE-2026-32352: WordPress Elementor Website Builder plugin <= 3.35.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows DOM-Based XSS.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32352?
CVE-2026-32352 is classified as a high-severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2026-32352?
To fix CVE-2026-32352, update the Elementor Website Builder plugin to version 3.35.6 or later.
What versions of Elementor are affected by CVE-2026-32352?
CVE-2026-32352 affects Elementor Website Builder plugin versions up to and including 3.35.5.
What kind of attacks can CVE-2026-32352 enable?
CVE-2026-32352 can enable attackers to execute arbitrary JavaScript in the context of the affected user's session.
Is CVE-2026-32352 a potential threat to my WordPress site?
Yes, if you are using an affected version of the Elementor plugin, your WordPress site is vulnerable to CVE-2026-32352.