CVE-2020-20634: Elementor Website Builder

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

Affected products

  • Elementor Website Builder: up to and including 2.9.5

Published 2020-08-21. Last modified 2026-06-17.