Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Website Builder MEDIUM 6.1
CVE-2021-24891EPSS 25%

The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resultin…

Fix: 3.1.4 / 3.4.8+
Fix from $1,600 2021-11-23
Website Builder MEDIUM 5.4
CVE-2021-24203

In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Al…

Fix: 3.1.4+
Fix from $1,600 2021-04-05
Website Builder MEDIUM 5.4
CVE-2021-24204

In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ para…

Fix: 3.1.4+
Fix from $1,600 2021-04-05
Website Builder MEDIUM 5.4
CVE-2021-24205

In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter.…

Fix: 3.1.4+
Fix from $1,600 2021-04-05
Website Builder MEDIUM 5.4
CVE-2021-24206

In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ paramete…

Fix: 3.1.4+
Fix from $1,600 2021-04-05
Website Builder MEDIUM 5.4
CVE-2021-24201

In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Al…

Fix: 3.1.4+
Fix from $1,600 2021-04-05
Website Builder MEDIUM 5.4
CVE-2021-24202

In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. …

Fix: 3.1.4+
Fix from $1,600 2021-04-05
Website Builder MEDIUM 6.1
CVE-2020-36171

The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.

Fix: 3.0.14+
Fix from $1,600 2021-01-06
Elementor Pro HIGH 8.8
CVE-2020-26596EPSS 6%

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because o…

Fix: after 3.0.5
Fix from $1,950 2020-10-07
Elementor Page Builder MEDIUM 5.4
CVE-2020-20406

A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is c…

Fix: after 2.9.2
Fix from $1,600 2020-09-16
Website Builder MEDIUM 5.4
CVE-2020-15020

An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Temp…

Fix: after 2.9.13
Fix from $1,600 2020-08-31
Website Builder MEDIUM 6.5
CVE-2020-20634

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all securit…

Fix: after 2.9.5
Fix from $1,600 2020-08-21
Elementor Page Builder MEDIUM 5.4
CVE-2020-13864

The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in …

Fix: 2.9.9+
Fix from $1,600 2020-06-05
Elementor Page Builder MEDIUM 5.4
CVE-2020-13865

The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that r…

Fix: 2.9.9+
Fix from $1,600 2020-06-05
Elementor Page Builder CRITICAL 9.9
CVE-2020-13126EPSS 9%

An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-131…

Fix: 2.9.4+
Fix from $2,300 2020-05-17
Elementor Page Builder CRITICAL 9.9
CVE-2020-7055

An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to exe…

Fix: after 2.7.4
Fix from $2,300 2020-04-22
Website Builder MEDIUM 5.4
CVE-2020-8426

The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited …

Fix: 2.8.5+
Fix from $1,600 2020-01-28
Website Builder CRITICAL 9.8
CVE-2020-7109

The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

Fix: 2.8.4+
Fix from $2,300 2020-01-22
Elementor Page Builder MEDIUM 6.1
CVE-2018-18379

The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.

Fix: 2.0.10+
Fix from $1,600 2019-10-07
Elementor Page Builder HIGH 8.8
CVE-2017-18596

The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.

Fix: 1.8.0+
Fix from $1,950 2019-09-10