WordPress security by component
Elementor Website Builder
Plugin description
Elementor Website Builder provides a visual drag-and-drop editor for creating and customizing WordPress pages, posts, templates, and website layouts.
Elementor Website Builder (website-builder) is a WordPress plugin with 20 published CVE records in this archive. The latest tracked vulnerability was published Sep 22, 2025; the highest published CVSS base score is 8.8.
Plugin slug:
website-builderLatest vulnerability
CVE-2025-58033: Draft: Cross-site scripting
Draft is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Sep 22, 2025 |
CVE-2025-58033
Draft: Cross-site scripting
Draft is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Jul 29, 2025 |
CVE-2025-3075
Elementor Website Builder – More Than Just a Page Builder: Cross-site scripting
Elementor Website Builder – More Than Just a Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 25, 2025 |
CVE-2024-54444
Elementor Website Builder: Cross-site scripting
Elementor Website Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 20, 2025 |
CVE-2024-13445
Elementor Website Builder – More Than Just a Page Builder: Cross-site scripting
Elementor Website Builder – More Than Just a Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 30, 2025 |
CVE-2024-8494
Elementor Website Builder Pro: Sensitive information exposure
Elementor Website Builder Pro is affected by sensitive information exposure. Exploitation requires an authenticated contributor account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVD6.5
|
| May 14, 2024 |
CVE-2024-4107
Elementor Website Builder – More than Just a Page Builder Pro: Cross-site scripting
Elementor Website Builder – More than Just a Page Builder Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 09, 2024 |
CVE-2024-2117
Elementor Website Builder – More than Just a Page Builder: Cross-site scripting
Elementor Website Builder – More than Just a Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 27, 2024 |
CVE-2024-2120
Elementor Website Builder Pro: Cross-site scripting
Elementor Website Builder Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 14, 2023 |
CVE-2022-4953
Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jun 07, 2023 |
CVE-2020-36703
Elementor Website Builder: Cross-site scripting
Elementor Website Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 30, 2023 |
CVE-2023-0329
Elementor Website Builder: SQL injection
Elementor Website Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Apr 19, 2022 |
CVE-2022-1329
Elementor Website Builder: Code execution
Elementor Website Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Nov 23, 2021 |
CVE-2021-24891
Elementor Website Builder: Cross-site scripting
Elementor Website Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Apr 05, 2021 |
CVE-2021-24206
Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Apr 05, 2021 |
CVE-2021-24205
Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Apr 05, 2021 |
CVE-2021-24204
Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Apr 05, 2021 |
CVE-2021-24203
Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Apr 05, 2021 |
CVE-2021-24202
Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Apr 05, 2021 |
CVE-2021-24201
Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Aug 21, 2020 |
CVE-2020-20634
Website Builder: A security weakness
Website Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.5
|