Elementor vulnerabilities
3 CVEs tracked
Elementor, a widely-used WordPress page builder, appears in recent reports primarily due to security issues within its extension plugins. Key themes include the upload of malicious SVG files by Author-level users via the 'Animation Addons for Elementor' plugin (CVE-2026-13330) and sensitive information exposure through the 'Jeg Kit for Elementor' plugin (CVE-2026-2916). A critical incident involves a flaw in Elementor Pro itself, allowing unauthenticated PHP upload and remote code execution (CVE-2026-32475). Defenders should prioritize updating Elementor Pro to the latest version and patching all associated Elementor add-on plugins, as these vulnerabilities present active exploitation risks.
Azərbaycanca: Elementor, WordPress üçün populyar səhifə qurucusu olaraq, son hesabatlarda əsasən onun genişləndirmə (add-on) plaginlərindəki təhlükəsizlik problemləri ilə gündəmə gəlir. Əsas mövzular daxildir: 'Animation Addons for Elementor' plagini vasitəsilə Author səviyyəli istifadəçilər tərəfindən zərərli SVG fayllarının yüklənməsi (CVE-2026-13330) və 'Jeg Kit for Elementor' plagini ilə həssas məlumatların ifşası (CVE-2026-2916). Kritik bir hadisə isə Elementor Pro-nun özündə aşkarlanan, autentifikasiya olunmamış PHP yükləməsinə və kod icrasına imkan verən boşluqdur (CVE-2026-32475). Müdafiəçilər diqqəti xüsusilə Elementor Pro-nu ən son versiyaya yeniləməyə və bütün əlavə Elementor plaginlərinin yamaqlarını tətbiq etməyə yönəltməlidir, çünki zəifliklər aktiv şəkildə istismar oluna bilər.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Elementor: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.