Vulnerabilities > Elementor > Website Builder > 1.7.7

DATE CVE VULNERABILITY TITLE RISK
2021-04-05 CVE-2021-24202 Cross-site Scripting vulnerability in Elementor Website Builder
In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter.
network
elementor CWE-79
3.5
2021-04-05 CVE-2021-24201 Cross-site Scripting vulnerability in Elementor Website Builder
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter.
network
low complexity
elementor CWE-79
5.4
2020-08-31 CVE-2020-15020 Cross-site Scripting vulnerability in Elementor Website Builder
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress.
network
low complexity
elementor CWE-79
5.4
2020-08-21 CVE-2020-20634 Unspecified vulnerability in Elementor Website Builder
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature.
network
low complexity
elementor
6.5
2020-01-28 CVE-2020-8426 Cross-site Scripting vulnerability in Elementor Website Builder
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page.
network
low complexity
elementor CWE-79
5.4
2020-01-22 CVE-2020-7109 Unspecified vulnerability in Elementor Website Builder
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
network
low complexity
elementor
critical
9.8