CVE-2020-20406: Elementor Page Builder

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.

Affected products

  • Elementor Elementor Page Builder: up to and including 2.9.2

Published 2020-09-16. Last modified 2026-06-17.