Known vulnerabilities in the Elementor Forms plugin
11 security advisories have been published for the Elementor Forms plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Elementor Forms - SQL Injection (CVE-2026-14872) MEDIUM
- Elementor Forms - Cross-Site Scripting (XSS) (CVE-2026-14870) HIGH
- Elementor Forms - PHP Object Injection (CVE-2026-12081) MEDIUM
- Elementor Forms - Security Vulnerability (CVE-2026-9145) MEDIUM
- Elementor Forms - Remote Code Execution (CVE-2026-9843) HIGH
- Elementor Forms - Broken Access Control (CVE-2026-3831) MEDIUM
- Elementor Forms - PHP Object Injection (CVE-2026-2599) CRITICAL
- Elementor Forms - Broken Access Control (CVE-2026-0825) MEDIUM
- Elementor Forms - Remote Code Execution (CVE-2025-7384) CRITICAL
- Elementor Forms - Cross-Site Scripting (XSS) (CVE-2024-3715) HIGH
- Elementor Forms - Cross-Site Scripting (XSS) (CVE-2024-2030) MEDIUM