Where
-Infinity
0

Elementor ElementorElementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import

Risk 22
Severity
4.9
EPSS
0.05%
First published (updated )

Elementor Website BuilderElementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Elementor Elementor Website BuilderWordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
First published (updated )

Elementor Website BuilderElementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Elementor Website Builder WordPressElementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Website BuilderElementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings

Risk 39
Severity
6.4
First published (updated )

Elementor Website BuilderElementor Website Builder – More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Elementor Website Builder WordPressElementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function

Risk 22
Severity
4.3
First published (updated )

Elementor Website Builder WordPressElementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets

Risk 34
Severity
5.4
First published (updated )

Elementor Website Builder WordPressWordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerability

Risk 34
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Website Builder WordPressWordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability

Risk 22
Severity
4.3
First published (updated )

Elementor Website BuilderElementor Website Builder – More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

Risk 28
Severity
6.4
EPSS
0.05%
First published (updated )

Elementor Website Builder WordPressWordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability

Risk 73
Severity
8.5
First published (updated )

Elementor Website Builder WordPressElementor Website Builder Pro <= 3.21.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

Risk 28
Severity
6.4
EPSS
0.04%
First published (updated )

Elementor Website BuilderWordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Website BuilderElementor Website Builder – More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget

Risk 39
Severity
6.4
First published (updated )

Elementor Website BuilderElementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

Elementor Website Builder WordPressWordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability

Risk 82
Severity
9.9
First published (updated )

Elementor Website BuilderElementor Website Builder – More than Just a Page Builder <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt

Risk 39
Severity
6.4
First published (updated )

Elementor Website Builder WordPressWordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS)

Risk 46
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Website Builder WordPressElementor Website Builder <= 2.9.7 - Authenticated Stored Cross-Site Scripting

Risk 40
Severity
6.4
First published (updated )

Elementor Website Builder WordPressWordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability

Risk 38
Severity
6.1
First published (updated )

Elementor Website Builder WordPressElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget

Risk 34
Severity
5.4
First published (updated )

Elementor Website Builder WordPressElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget

Risk 34
Severity
5.4
First published (updated )

Elementor Website Builder WordPressElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Elementor Website Builder WordPressElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget

Risk 34
Severity
5.4
First published (updated )

Elementor Website Builder WordPressElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element

Risk 34
Severity
5.4
First published (updated )

Elementor Website Builder WordPressElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget

Risk 34
Severity
5.4
First published (updated )

Elementor Website Builder WordPressXSS

Risk 34
Severity
5.4
First published (updated )

Elementor Website Builder WordPressThe Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation …

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203