CVE-2024-24934: Elementor Website Builder

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.

Affected products

  • Elementor Website Builder: before 3.19.1 (fixed in 3.19.1)

Published 2024-05-17. Last modified 2026-06-17.