CVE-2020-15020: Elementor Website Builder
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
Affected products
- Elementor Website Builder: up to and including 2.9.13
Published 2020-08-31. Last modified 2026-06-17.