CVE-2020-13865: Elementor Page Builder
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
Affected products
- Elementor Elementor Page Builder: before 2.9.9 (fixed in 2.9.9)
Published 2020-06-05. Last modified 2026-06-17.