Known vulnerabilities in the Elementor Website Builder plugin
9 security advisories have been published for the Elementor Website Builder plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Elementor Website Builder - Broken Access Control (CVE-2026-8825) MEDIUM
- Elementor Website Builder - Security Vulnerability (CVE-2026-57619) MEDIUM
- Elementor Website Builder - Cross-Site Scripting (XSS) (CVE-2026-6127) MEDIUM
- Elementor Website Builder - Broken Access Control (CVE-2026-1206) MEDIUM
- Elementor Website Builder - Broken Access Control (CVE-2026-32445) LOW
- Elementor Website Builder - Cross-Site Scripting (XSS) (CVE-2026-32352) MEDIUM
- Elementor Website Builder - SQL Injection (CVE-2023-0329) HIGH
- Elementor Website Builder - Remote Code Execution (CVE-2022-1329) HIGH
- Elementor Website Builder - Cross-Site Scripting (XSS) (CVE-2021-24891) MEDIUM