Vulnerabilities > Elementor > Website Builder
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-04-05 | CVE-2021-24202 | Cross-site Scripting vulnerability in Elementor Website Builder In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. | 5.4 |
2021-04-05 | CVE-2021-24201 | Cross-site Scripting vulnerability in Elementor Website Builder In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. | 5.4 |
2021-01-06 | CVE-2020-36171 | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads. | 6.1 |
2020-08-31 | CVE-2020-15020 | Cross-site Scripting vulnerability in Elementor Website Builder An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. | 5.4 |
2020-08-21 | CVE-2020-20634 | Unspecified vulnerability in Elementor Website Builder Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. | 6.5 |
2020-01-28 | CVE-2020-8426 | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. | 5.4 |
2020-01-22 | CVE-2020-7109 | Unspecified vulnerability in Elementor Website Builder The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. | 9.8 |