The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts sites with 'Element Caching' enabled.
We have discovered 960,672 live websites that are affected by CVE-2025-3075.
| Product | |
| Category | Landing Page Builders |
| Vulnerable Domains | 960,672 live websites (37% of Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 286 versions ( 89% of all versions) |
| 222,901 websites | |
| 98,987 websites | |
| 54,909 websites | |
| 45,420 websites | |
| 41,577 websites | |
| 36,196 websites | |
| 31,998 websites | |
| 29,822 websites | |
| 27,971 websites | |
| 25,455 websites |
| .com | 376,518 websites |
| .de | 53,688 websites |
| .com.br | 38,899 websites |
| .org | 35,563 websites |
| .it | 32,817 websites |
| .fr | 22,950 websites |
| .nl | 22,892 websites |
| .pl | 22,729 websites |
| .ru | 21,997 websites |
| .net | 20,787 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.de | *** | ||
| ************.com | *,*** | ||
| ****.net | *,*** | ||
| ***********.com | *,*** | ||
| ***.***.ca | *,*** | ||
| ********.com | *,*** | ||
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| *****.com | *,*** | ||
| ******.com | *,*** |
FAQ