Vulnerabilities (CVE)

Filtered by vendor Elementor Subscribe
Filtered by product Elementor Page Builder
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13126 1 Elementor 1 Elementor Page Builder 2020-05-18 6.5 MEDIUM 9.9 CRITICAL
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
CVE-2020-7055 1 Elementor 1 Elementor Page Builder 2020-04-28 9.0 HIGH 9.9 CRITICAL
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
CVE-2020-7109 1 Elementor 1 Elementor Page Builder 2020-01-24 7.5 HIGH 9.8 CRITICAL
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.