Elementor — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
November 21, 2025
Last Seen
June 16, 2026

Elementor is a widely used WordPress page builder/plugin platform that enables visual site design and layout customization.

Overview

Elementor is a widely used WordPress page builder/plugin platform that enables visual site design and layout customization. Recent reports highlight critical vulnerabilities in Elementor's ecosystem (notably King Addons) that can grant attackers admin privileges or full control of WordPress sites, underscoring significant risk to millions of WordPress deployments and active exploitation.

Related Threat Clusters

Recent Intelligence Reports

  • CRITICAL: CVE-2026-49105 (CVSS 9.8) — multiple products — Lyrie.Ai · June 16, 2026
  • 20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation — Cybersecuritynews · January 23, 2026
  • King Addons flaw lets anyone become WordPress admin — Securityaffairs.Co · December 3, 2025
  • Critical flaw in WordPress add — Bleepingcomputer · December 3, 2025
  • Critical King Addons Vulnerability Exploited to Hack WordPress Sites — Securityweek · December 3, 2025
  • Critical King Addons Vulnerability Exploited to Hack WordPress Sites — Feeds.Feedburner · December 3, 2025
  • Critical Elementor Plugin Flaw Allows Attackers to Seize WordPress Admin Control — Gbhackers · December 3, 2025
  • Cache of Doom: WordPress Plugin Flaw Exposes Millions to Cyber Havoc — Webpronews · November 21, 2025

CVSS v3.1 Breakdown