Vulnerabilities > Elementor > Website Builder

DATE CVE VULNERABILITY TITLE RISK
2021-11-23 CVE-2021-24891 Cross-site Scripting vulnerability in Elementor Website Builder
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
network
elementor CWE-79
4.3
2021-04-05 CVE-2021-24206 Cross-site Scripting vulnerability in Elementor Website Builder
In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter.
network
elementor CWE-79
3.5
2021-04-05 CVE-2021-24205 Cross-site Scripting vulnerability in Elementor Website Builder
In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter.
network
elementor CWE-79
3.5
2021-04-05 CVE-2021-24204 Cross-site Scripting vulnerability in Elementor Website Builder
In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter.
network
elementor CWE-79
3.5
2021-04-05 CVE-2021-24203 Cross-site Scripting vulnerability in Elementor Website Builder
In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter.
network
elementor CWE-79
3.5
2021-04-05 CVE-2021-24202 Cross-site Scripting vulnerability in Elementor Website Builder
In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter.
network
elementor CWE-79
3.5
2021-04-05 CVE-2021-24201 Cross-site Scripting vulnerability in Elementor Website Builder
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter.
network
low complexity
elementor CWE-79
5.4
2021-01-06 CVE-2020-36171 Cross-site Scripting vulnerability in Elementor Website Builder
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
network
elementor CWE-79
4.3
2020-08-31 CVE-2020-15020 Cross-site Scripting vulnerability in Elementor Website Builder
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress.
network
low complexity
elementor CWE-79
5.4
2020-08-21 CVE-2020-20634 Unspecified vulnerability in Elementor Website Builder
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature.
network
low complexity
elementor
6.5