📦 Website Builder

by Elementor

🔍 What is Website Builder?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-47504

HIGH CVSS 7.5 Apr 24, 2024

This CVE describes an improper authentication vulnerability in Elementor Website Builder that allows users with contributor-level access to read arbitrary attachments they shouldn't have permission to...

CVE-2023-0329

HIGH CVSS 7.2 May 30, 2023

This vulnerability allows authenticated administrators in WordPress sites using the Elementor Website Builder plugin to perform SQL injection attacks via the Replace URL parameter in the Tools module....

CVE-2022-1329

HIGH CVSS 8.8 Apr 19, 2022

This vulnerability in the Elementor Website Builder plugin for WordPress allows authenticated attackers to execute unauthorized AJAX actions due to missing capability checks. Attackers can modify site...

CVE-2024-10453

MEDIUM CVSS 6.4 Dec 21, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into website pages through Elementor's typography settings. The scripts exec...

CVE-2024-8236

MEDIUM CVSS 6.4 Nov 26, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into website pages via the Elementor Icon widget. The stored XSS payload exe...

CVE-2024-5416

MEDIUM CVSS 5.4 Sep 11, 2024

This stored XSS vulnerability in Elementor WordPress plugin allows authenticated attackers with contributor-level access or higher to inject malicious scripts via URL parameters in multiple widgets. T...

CVE-2023-33922

MEDIUM CVSS 4.3 Jun 11, 2024

This CVE describes a missing authorization vulnerability in Elementor Website Builder for WordPress. It allows unauthorized users to perform actions that should require proper authentication, affectin...

CVE-2024-4107

MEDIUM CVSS 6.4 May 14, 2024

This stored XSS vulnerability in Elementor Pro plugin allows authenticated attackers with contributor-level permissions or higher to inject malicious scripts into WordPress pages. When users visit com...