Elementor Website Builder – more than just a page builder
by Elementor · Page Builders
Also makes 13 other plugins · 12.3M+ installs across the portfolio →
The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel perfect design, global and reusable style systems, mobile r …
92 health vs 69 average across 1,269 Page Builders plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
13.6M
now · peak 34.6M
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
93
releases in the last 12 months
1mo ago
latest release · v4.1.5
443
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “10M+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2016-09-16 · 1,473 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
A large install base, a clear pro tier and a steady trend. As reliable as an outside estimate gets. The range spans more than 10x because wp.org publishes install counts as broad bands, and conversion and price compound on top. Read the midpoint as an order of magnitude, not a valuation.
How we estimate this
Assumptions
- Free → paid conversion. 0.5%–2% of active installs pay for the pro tier. Typical for freemium WordPress plugins; the real rate varies a lot by product. Past 1M installs we taper the rate down: a giant free plugin’s long tail converts far worse.
- Annual price per customer. $49–$99 a year, typical for Page Builders plugins rather than this plugin's own pricing.
- Acquisition multiple. 2.5x–4.5x annual revenue, the going range for small WordPress-plugin businesses, stretched a little because downloads are growing.
- Install base. 10M–20M active installs, from our install estimate (wp.org only publishes the floor).
Inputs
- Active installs
- 10M–20M
- Category
- Page Builders
- Pro tier
- detected (known freemium plugin with a public paid tier)
- Download trend
- growing (30d downloads up vs prior 30d)
- Reviews
- 7,296
- Last updated
- 6 days ago
Revenue is installs × conversion × price; value is revenue × a typical acquisition multiple. Every factor is an assumption band, so the output is a wide range on purpose. If you're buying or selling, treat this as a starting point for due diligence.
Details
Recent review vibe
read from the latest 12 reviews to 2026-07-19Reviewers describe broken updates, unresolved support tickets, and heavy performance and compatibility problems, with only a couple of positive voices mixed in.
Recent reviews
All reviews on wp.org ↗- ★★★★★ jonyshanto1mo ago
The plugin is updated regularly, but the lagging issues and functionality problems are never fixed. This topic was modified 1 day, 1 hour ago by jonyshanto.
Read on wp.org ↗ - ★★★★★ Anonymous1mo ago
Really difficult and time consuming to work with, and mixing old and new Atomic layouts is quite the mess to work with, but the end-result usually looks worth.
Read on wp.org ↗ - ★★★★★ hussainmirza111mo ago
While Elementor is easy to use, it adds a significant amount of CSS and JavaScript. On larger websites, this can negatively impact loading speed and overall performance. There are also occasional compatibility issues after updates, which can be frustrating.
Read on wp.org ↗ - ★★★★★ Maria del Castillo1mo ago
Still waiting for support to fix the atomic designer. After a recent update my website broke completely (error with containers) and after more than a month I’m still waiting for support to fix it. They admited it is a problem on their side, but still haven’t done anything to solve it. Would not recommend this plugin anymore.
Read on wp.org ↗ - ★★★★★ Thierry Laval2mo ago
Elementor is an excellent page builder, but my frustration, as well as that of my clients regarding the repeated display of promotional messages in the dashboard, leads me to give it only one star. It is becoming extremely annoying to see advertising everywhere, including inside an administration area that should remain a clean and professional workspace. This constant promotion creates a strong rejection of the product instead of encouraging users to continue using Elementor. Users should be given a simple option to disable these promotional messages and keep control over their own workspace.
Read on wp.org ↗ - ★★★★★ ashlyjohny2mo ago
The plugin is good and offers useful features, but the learning curve is quite steep for new users. Better documentation or beginner-friendly tutorials would make it much easier to get started. This topic was modified 1 week, 5 days ago by ashlyjohny.
Read on wp.org ↗ - ★★★★★ ethanmaller2mo ago
Elementor was key in helping us implement our designs across our pages and blogs. It was an interesting learning curve at first, but everything clicked once we understood the logic.
Read on wp.org ↗ - ★★★★★ updesignme2mo ago
I am very disappointed with Elementor. V4 is utterly unreliable and causing all kinds of erratic behaviour and difficulties. There is limited help resources available, and just don’t try to contact support, because everything will your fault. I have already moved my hosting away. Seems it’s time to look for a new page builder too. Not happy Elementor!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-08-19 Version 4.2.3 Fix: Improved code security enforcement in template handling Fix: Invalid style properties prevent pages from being published 4.2.3
- 2026-08-06 Version 4.2.2 Fix: Editor top bar integrations may not appear in non-English languages 4.2.2
- 2026-07-28 Version 4.2.1 Fix: Improved code security enforcement in template handling Fix: Improved code security enforcement in document handling Fix: Invalid border-radius values in Global Classes prevent class changes – Atomic Editor Fix: Ato 4.2.1
- 2026-07-20 Version 4.2.0 New: Introducing Grid for building advanced row and column layouts – Atomic Editor Tweak: Improved Angie layout, composition, and design system creation from prompts and images – Atomic Editor Tweak: Added dynamic tag su 4.2.0
- 2026-07-14 Version 4.1.5 Fix: AI features may not initialize correctly when opening the editor 4.1.5
- 2026-06-21 Version 4.1.4 Fix: Improved code security enforcement in query handling 4.1.4
Known vulnerabilities
via Wordfence Intelligence53 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-06-29 CVE-2026-8825 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.1.3 Patched in 4.1.4
- 2026-06-25 CVE-2026-57619 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.1.3 Patched in 4.1.4
- Medium · 6.4 Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ↗2026-04-30 CVE-2026-6127 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.0.4 Patched in 4.0.5
- Medium · 6.4 Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ↗2026-04-07 CVE-2025-14732 Improper Neutralization of Alternate XSS Syntax Affects <= 3.35.5 Patched in 3.35.6
- 2026-03-25 CVE-2026-1206 Authorization Bypass Through User-Controlled Key Affects <= 3.35.7 Patched in 3.35.8
- Medium · 6.4 Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2026-02-13 CVE-2026-32352 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.35.5 Patched in 3.35.6
- Medium · 6.4 Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path ↗2025-12-15 CVE-2025-11220 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.33.3 Patched in 3.33.4
- Medium · 4.9 Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import ↗2025-08-11 CVE-2025-8081 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.30.2 Patched in 3.30.3
- 2025-07-28 CVE-2025-3075 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.29.0 Patched in 3.29.1
- Medium · 6.4 Elementor <= 3.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget ↗2025-07-28 CVE-2025-4566 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.30.2 Patched in 3.30.3
- Medium · 6.4 Elementor Website Builder <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2025-06-19 CVE-2024-50555 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.29.0 Patched in 3.29.1
- Medium · 6.4 Elementor Website Builder <= 3.25.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2025-02-24 CVE-2024-54444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.25.10 Patched in 3.25.11
- 2025-02-19 CVE-2024-13445 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.27.4 Patched in 3.27.5
- 2024-12-20 CVE-2024-10453 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.25.9 Patched in 3.25.10
- 2024-11-25 CVE-2024-8236 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.25.7 Patched in 3.25.8
- Medium · 4.3 Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function ↗2024-10-14 CVE-2024-6757 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.24.5 Patched in 3.24.6
- 2024-09-10 CVE-2024-5416 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.23.4 Patched in 3.24.0
- Medium · 6.4 Elementor Website Builder <= 3.22.1 - Authenticated (Contributor+) Arbitrary SVG Download ↗2024-06-28 CVE-2024-37437 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.22.1 Patched in 3.22.2
- 2024-05-20 CVE-2024-4619 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.21.5 Patched in 3.21.6
- 2024-03-26 CVE-2024-2117 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.20.2 Patched in 3.20.3
- 2024-02-07 CVE-2024-0506 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.18.3 Patched in 3.19.0
- High · 8.8 Elementor <= 3.19.0 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization ↗2024-02-07 CVE-2024-24934 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.19.0 Patched in 3.19.1
- 2023-12-06 CVE-2023-48777 Unrestricted Upload of File with Dangerous Type Affects <= 3.18.1 Patched in 3.18.2
- Medium · 6.4 Elementor Website Builder <= 3.16.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg() ↗2023-11-08 CVE-2023-47505 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.16.4 Patched in 3.16.5
- Medium · 6.1 Elementor <= 3.5.4 - DOM-Based iFrame Injection ↗2023-07-19 CVE-2022-4953 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.5.4 Patched in 3.5.5
- 2023-05-12 Missing Authorization Affects <= 3.13.1 Patched in 3.13.2
- 2023-04-24 CVE-2023-0329 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.12.2 Patched in 3.12.2
- Medium · 6.1 Elementor Website Builder <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting ↗2022-06-13 CVE-2022-29455 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.5.5 Patched in 3.5.6
- 2021-03-23 CVE-2021-24891 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 0.1.0 - 3.4.7 Patched in 3.4.8
- Medium · 6.4 Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_html_tag ↗2021-03-17 CVE-2021-24204 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.3 Patched in 3.1.4
- Medium · 6.4 Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_size ↗2021-03-17 CVE-2021-24206 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 0.1.0 - 3.1.3 Patched in 3.1.4
- Medium · 6.4 Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag ↗2021-03-17 CVE-2021-24201 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 0.1.0 - 3.1.3 Patched in 3.1.4
- 2021-03-17 CVE-2021-24205 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.1.4 Patched in 3.1.4
- Medium · 6.4 Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via header_size ↗2021-03-17 CVE-2021-24202 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 0.1.0 - 3.1.3 Patched in 3.1.4
- Medium · 6.4 Elementor Website Builder <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag ↗2021-03-17 CVE-2021-24203 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 0.1.0 - 3.1.3 Patched in 3.1.4
- 2020-11-25 CVE-2020-36171 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.13 Patched in 3.0.14
- 2020-07-07 CVE-2020-15020 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.14 Patched in 2.9.14
- 2020-06-05 CVE-2020-13864 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.8 Patched in 2.9.9
- 2020-06-05 CVE-2020-13865 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.8 Patched in 2.9.9
- 2020-04-21 CVE-2020-36703 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.7 Patched in 2.9.8
- 2020-02-26 CVE-2020-20406 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.2 Patched in 2.9.3
- 2020-01-29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.5 Patched in 2.7.6
- 2020-01-29 CVE-2020-8426 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.4 Patched in 2.8.5
- 2020-01-19 CVE-2020-7109 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.3 Patched in 2.8.4
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 89 languages, 18 at 90% or more
Plus 65 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2024-05-23 5M+ → 10M+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder 10K+ installs · 4.0★ · 5 shared tags B -
Page Builder: Pagelayer – Drag and Drop website builder 400K+ installs · 3.9★ · 4 shared tags B -
Colibri Page Builder 90K+ installs · 4.4★ · 4 shared tags A -
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor 50K+ installs · 4.7★ · 3 shared tags A -
Bold Page Builder 40K+ installs · 3.6★ · 3 shared tags B -
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode 700K+ installs · 4.9★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for Elementor Website Builder – more than just a page builder into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/elementor" width="480" height="300" style="border:0" loading="lazy" title="Elementor Website Builder – more than just a page builder — Plugin Pulse"></iframe> Elementor Website Builder – more than just a page builder: 10M+ active installs, 4.5★ (7,296 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/elementor