Where
-Infinity
0

Elementor Ultimate Addons for ElementorUltimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes

Risk 39
Severity
6.4
First published (updated )

Elementor Elementor Website BuilderElementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API

Risk 22
Severity
4.9
EPSS
0.23%
First published (updated )

Elementor Animation Addons for ElementorAnimation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget

Risk 39
Severity
6.4
First published (updated )

Elementor Elementor Website BuilderWordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerability

Risk 34
Severity
5.4
First published (updated )

Elementor Elementor Website BuilderElementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

Risk 28
Severity
6.4
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Elementor Website BuilderElementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

Risk 39
Severity
6.4
First published (updated )

Elementor Elementor Website BuilderElementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template

Risk 22
Severity
4.3
First published (updated )

BleepingComputerSQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites

First published (updated )

Elementor Testimonial Carousel For ElementorTestimonial Carousel For Elementor <= 11.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

Risk 39
Severity
6.4
First published (updated )

Elementor Countdown TimerCountdown Timer for Elementor <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'countdown_label'

Risk 39
Severity
6.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Events Addon for ElementorEvents Addon for Elementor <= 2.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typewriter and Countdown Widgets

Risk 28
Severity
6.4
EPSS
0.03%
First published (updated )

Elementor ElementorElementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import

Risk 22
Severity
4.9
EPSS
0.05%
First published (updated )

Elementor Website BuilderElementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Elementor Website BuilderElementor <= 3.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget

Risk 39
Severity
6.4
First published (updated )

Elementor Elementor Page Builder WordpressElementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Music Player for ElementorMusic Player for Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via album_buy_url Parameter

Risk 28
Severity
6.4
EPSS
0.03%
First published (updated )

Elementor Animation Addons for Elementor ProAnimation Addons for Elementor Pro <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

Risk 79
Severity
8.8
First published (updated )

Site Mailer Site MailerSite Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting

Risk 44
Severity
7.2
First published (updated )

Elementor Card Elements for ElementorCard Elements for Elementor <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Profile Card Widget

Risk 39
Severity
6.4
First published (updated )

Flickdevs Countdown Timer For Elementor WordpressCountdown Timer for Elementor < 1.3.7 - Contributor+ Stored XSS

Risk 40
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Elementor Website BuilderWordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
First published (updated )

Elementor Website BuilderElementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Elementor Website Builder WordPressElementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode

Risk 38
Severity
6.5
First published (updated )

Webtechstreet Elementor Addon Elements WordpressElementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup

Risk 22
Severity
4.3
First published (updated )

Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate ElementsElementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements <= 2.2.1 - Authenticated (Contributor+) Private Templates Content Disclosure

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Brainstormforce Elementor Header \& Footer Builder WordpressElementor Header & Footer Builder <= 1.6.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title Widget

Risk 39
Severity
6.4
First published (updated )

Elementor Website BuilderElementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings

Risk 39
Severity
6.4
First published (updated )

Elementor Full Screen MenuFull Screen Menu for Elementor <= 1.0.7 - Authenticated (Contributor+) Post Disclosure

Risk 22
Severity
4.3
First published (updated )

Elementor Events Addon for ElementorEvents Addon for Elementor <= 2.2.3 - Authenticated (Contributor+) Post Disclosure

Risk 23
Severity
4.3
First published (updated )

Elementor Restaurant & Cafe AddonRestaurant & Cafe Addon for Elementor <= 1.5.9 - Authenticated (Contributor+) Post Disclosure

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203