Cross-Site Scripting
35 records66%First: 2020. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 53 vulnerability records associated with Elementor Website Builder – more than just a page builder, published between 2017 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2017 | 1 | |
| 2019 | 1 | |
| 2020 | 10 | |
| 2021 | 7 | |
| 2022 | 2 | |
| 2023 | 7 | |
| 2024 | 9 | |
| 2025 | 8 | |
| 2026 | 8 |
| Severity | Records | Share |
|---|---|---|
| High | 6 | 11.3% |
| Medium | 47 | 88.7% |
First: 2020. Latest: 2026.
First: 2017. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2025.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.1.44.1.14.0.53.35.63.35.83.33.43.33.13.30.33.29.13.25.113.27.53.25.103.25.83.24.63.24.03.22.23.21.63.20.33.19.13.19.03.18.23.16.53.5.53.13.33.13.23.12.23.5.63.6.33.4.83.1.43.0.142.9.142.9.92.9.82.9.62.9.32.8.52.7.62.8.42.7.51.8.0Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.8.3 | Elementor Website Builder <= 2.8.3 - Cross-Site Scripting | January 19, 2020 | 2.8.4 | High |
[*, 2.7.5) | Elementor Website Builder <= 2.7.4 - Arbitrary File Upload | October 28, 2019 | 2.7.5 | High |
*-1.7.12 | Elementor Website Builder <= 1.7.12 - Missing Authorization | November 27, 2017 | 1.8.0 | High |
Selected source records
Published: June 29, 2026
Published: June 25, 2026
Published: June 2, 2026
Published: April 30, 2026
Published: April 7, 2026
Published: March 25, 2026
Published: March 7, 2026
Published: February 13, 2026
Published: February 7, 2024
Published: December 6, 2023
Published: April 13, 2022
Published: November 27, 2017
Published: October 28, 2019
Published: January 19, 2020
Published: April 24, 2023
Published: March 31, 2020
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.