The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityLow
RequirementsPresent
PrivilegesLow
User InteractionNone
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityLow
IntegrityLow
AvailabilityNone
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | PoC | E: U→P | 0.6 → 1.3 |
| 2026-07-21 | cve.org | initial, patch: Unavailable | 0.6 |
Affected Software
| Vendor | Product | Version |
|---|
| elementor | website_builder | ≤ 2.9.7 |
| elemntor | Elementor Website Builder – more than just a page builder | ≤ 2.9.7 |
Published: 2023-06-07