← WordPress Vulnerabilities
WordPress security by component

Elementor Website Builder

Elementor Website Builder is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 20, 2026; the highest CVE/CNA score is 4.9.

Plugin slug: elementor-website-builder

CVE-2026-8825: Elementor Website Builder: A security weakness

Elementor Website Builder is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.1.4.

PublishedJul 20, 2026
Known safe version4.1.4
Safe version
Jul 20, 2026 CVE-2026-8825
Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.1.4.
4.1.4
CVE4.9
NVDPending
Mar 26, 2026 CVE-2026-1206
Elementor Website Builder – more than just a page builder: Sensitive information exposure
Elementor Website Builder – more than just a page builder is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 3.35.7.
> 3.35.7
CVE4.3
NVDPending