CVE-2025-8081

Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import

The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.


We have discovered 1,514,831 live websites that are affected by CVE-2025-8081.

Run a Free Instant Scan




Affected Software

Product  Elementor
Category Landing Page Builders
Vulnerable Domains1,514,831 live websites (56% of Elementor install base)
Vulnerable Versions
  • from 0 through 3.30.2
Vulnerable Versions Count293 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Aug 12, 2025
  • Updated - Aug 12, 2025

Credits

  • Michael Mazzolini (finder)

Website Distribution by Country

Number of websites using CVE-2025-8081
United States401,781 websites



Germany141,326 websites
France83,522 websites
Italy66,097 websites
Brazil63,672 websites
GB63,106 websites
Spain52,541 websites
Netherlands44,528 websites
Poland41,771 websites
Russia33,327 websites

Website Distribution by TLD

Number of websites using CVE-2025-8081
.com625,313 websites
.de75,741 websites
.com.br59,587 websites
.org58,268 websites
.it48,546 websites
.nl37,919 websites
.co.uk36,022 websites
.fr34,770 websites
.net33,261 websites
.pl31,982 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-8081

Top websites that are affected by CVE-2025-8081. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.io France***
**************.de Germany***
************.com United States*,***
************.de Germany*,***
****.net United States*,***
***********.com United States*,***
*********.com United States*,***
***.***.ca Canada*,***
***********.com United States*,***
**********.com United States*,***
See full domain list

FAQ

CVE-2025-8081 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Elementor
A total of 1,514,831 websites have been identified as vulnerable to CVE-2025-8081, based on global website indexing conducted by WebTechSurvey.
The Elementor is affected by the CVE-2025-8081 vulnerability.
Elementor versions up to and including 3.30.2 are vulnerable to CVE-2025-8081.