The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
We have discovered 1,514,831 live websites that are affected by CVE-2025-8081.
| Product | |
| Category | Landing Page Builders |
| Vulnerable Domains | 1,514,831 live websites (56% of Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 293 versions ( 95% of all versions) |
| 401,781 websites | |
| 141,326 websites | |
| 83,522 websites | |
| 66,097 websites | |
| 63,672 websites | |
| 63,106 websites | |
| 52,541 websites | |
| 44,528 websites | |
| 41,771 websites | |
| 33,327 websites |
| .com | 625,313 websites |
| .de | 75,741 websites |
| .com.br | 59,587 websites |
| .org | 58,268 websites |
| .it | 48,546 websites |
| .nl | 37,919 websites |
| .co.uk | 36,022 websites |
| .fr | 34,770 websites |
| .net | 33,261 websites |
| .pl | 31,982 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.io | *** | ||
| **************.de | *** | ||
| ************.com | *,*** | ||
| ************.de | *,*** | ||
| ****.net | *,*** | ||
| ***********.com | *,*** | ||
| *********.com | *,*** | ||
| ***.***.ca | *,*** | ||
| ***********.com | *,*** | ||
| **********.com | *,*** |
FAQ