Cross-Site Scripting
35 records66%First: 2020. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 53 vulnerability records associated with Elementor Website Builder – more than just a page builder, published between 2017 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2017 | 1 | |
| 2019 | 1 | |
| 2020 | 10 | |
| 2021 | 7 | |
| 2022 | 2 | |
| 2023 | 7 | |
| 2024 | 9 | |
| 2025 | 8 | |
| 2026 | 8 |
| Severity | Records | Share |
|---|---|---|
| High | 6 | 11.3% |
| Medium | 47 | 88.7% |
First: 2020. Latest: 2026.
First: 2017. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2025.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.1.44.1.14.0.53.35.63.35.83.33.43.33.13.30.33.29.13.25.113.27.53.25.103.25.83.24.63.24.03.22.23.21.63.20.33.19.13.19.03.18.23.16.53.5.53.13.33.13.23.12.23.5.63.6.33.4.83.1.43.0.142.9.142.9.92.9.82.9.62.9.32.8.52.7.62.8.42.7.51.8.0Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.1.3 | Elementor <= 4.1.3 - Authenticated (Contributor+) Sensitive Information Exposure | June 29, 2026 | 4.1.4 | Medium |
*-4.1.3 | Elementor Website Builder – more than just a page builder <= 4.1.3 - Authenticated (Contributor+) Sensitive Information Exposure | June 25, 2026 | 4.1.4 | Medium |
*-4.1.0 | Elementor Website Builder – more than just a page builder <= 4.1.0 - Missing Authorization | June 2, 2026 | 4.1.1 | Medium |
*-4.0.4 | Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API | April 30, 2026 | 4.0.5 | Medium |
*-3.35.5 | Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API | April 7, 2026 | 3.35.6 | Medium |
*-3.35.7 | Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template | March 25, 2026 | 3.35.8 | Medium |
*-3.35.5 | Elementor Website Builder <= 3.35.5 - Missing Authorization | March 7, 2026 | 3.35.6 | Medium |
*-3.35.5 | Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting | February 13, 2026 | 3.35.6 | Medium |
*-3.33.3 | Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path | December 15, 2025 | 3.33.4 | Medium |
*-3.33.0 | Elementor Website Builder <= 3.33.0 - Missing Authorization | November 25, 2025 | 3.33.1 | Medium |
*-3.30.2 | Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import | August 11, 2025 | 3.30.3 | Medium |
*-3.30.2 | Elementor <= 3.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget | July 28, 2025 | 3.30.3 | Medium |
*-3.29.0 | Elementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | July 28, 2025 | 3.29.1 | Medium |
*-3.29.0 | Elementor Website Builder <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | June 19, 2025 | 3.29.1 | Medium |
*-3.25.10 | Elementor Website Builder <= 3.25.10 - Authenticated (Contributor+) Stored Cross-Site Scripting | February 24, 2025 | 3.25.11 | Medium |
*-3.27.4 | Elementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | February 19, 2025 | 3.27.5 | Medium |
*-3.25.9 | Elementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings | December 20, 2024 | 3.25.10 | Medium |
*-3.25.7 | Elementor Website Builder – More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | November 25, 2024 | 3.25.8 | Medium |
*-3.24.5 | Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function | October 14, 2024 | 3.24.6 | Medium |
*-3.23.4 | Elementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets | September 10, 2024 | 3.24.0 | Medium |
*-3.22.1 | Elementor Website Builder <= 3.22.1 - Authenticated (Contributor+) Arbitrary SVG Download | June 28, 2024 | 3.22.2 | Medium |
*-3.21.5 | Elementor Website Builder – More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | May 20, 2024 | 3.21.6 | Medium |
*-3.20.2 | Elementor Website Builder – More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget | March 26, 2024 | 3.20.3 | Medium |
*-3.19.0 | Elementor <= 3.19.0 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization | February 7, 2024 | 3.19.1 | High |
*-3.18.3 | Elementor Website Builder – More than Just a Page Builder <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt | February 7, 2024 | 3.19.0 | Medium |
Selected source records
Published: June 29, 2026
Published: June 25, 2026
Published: June 2, 2026
Published: April 30, 2026
Published: April 7, 2026
Published: March 25, 2026
Published: March 7, 2026
Published: February 13, 2026
Published: February 7, 2024
Published: December 6, 2023
Published: April 13, 2022
Published: November 27, 2017
Published: October 28, 2019
Published: January 19, 2020
Published: April 24, 2023
Published: March 31, 2020
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.