Elementor A.I CyberSecurity Scoring
Elementor
Company Information
Website:https://go.elementor.com/homepage
Employees number:509
Number of followers:73,003
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:elementor.com
Elementor Risk Score (AI oriented)
Between 750 and 799
ElementorTechnology, Information and Internet
Updated:
12/03/2026
12/03/2026
755/1000
Fair
Baa
Elementor Global Score (TPRM)
xxxx
ElementorTechnology, Information and Internet
Score locked

ElementorFair
Current Score
755Baa (FAIR)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
755
MAY 2026
755
APRIL 2026
755
MARCH 2026
755
FEBRUARY 2026
772
Vulnerability
23 Feb 2026 • Elementor
WordPress and Elementor: Another worrying WordPress plugin security flaw could put 250,000 websites at risk
High-Severity SQL Injection Flaw in Ally WordPress Plugin Exposed 246,600 Sites
755
LOW-17
ELEWOR1773333877
High-Severity SQL Injection Flaw in Ally WordPress Plugin Exposed 246,600 Sites
A critical SQL injection vulnerability (CVE-2026-2413) in the Ally WordPress plugin a web accessibility tool from Elementor left approximately 246,600 websites vulnerable to data theft. The flaw, discovered by security researcher Drew Webber of Acquia, allowed unauthenticated attackers to inject malicious SQL queries into databases, enabling the extraction of sensitive information via time-based blind SQL injection techniques.
The vulnerability, rated 7.5/10 (high severity), affected all versions of Ally up to 4.0.3. It was patched on February 23 with the release of version 4.1.0. Despite over 400,000 active installations, only 38.4% (153,600 sites) had updated to the secure version at the time of disclosure, leaving the majority exposed.
WordPress, which has long emphasized the security risks posed by third-party plugins, urged users to immediately update both Ally and the core platform. WordPress 6.9.2, released recently, addressed 10 vulnerabilities, including XSS, authorization bypass, and SSRF flaws.
The incident underscores the persistent threat of plugin-based vulnerabilities in the WordPress ecosystem, where outdated or unsupported extensions remain a primary attack vector.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
772
DECEMBER 2025
772
NOVEMBER 2025
772
OCTOBER 2025
772
SEPTEMBER 2025
772
AUGUST 2025
772
JULY 2025
772
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Elementor ??
What was Elementor's A.I Rankiteo Cyber Score in May 2026 ??
What was Elementor's A.I Rankiteo Cyber Score in April 2026 ??
What was Elementor's A.I Rankiteo Cyber Score in March 2026 ??
What was Elementor's A.I Rankiteo Cyber Score in February 2026 ??
What was Elementor's A.I Rankiteo Cyber Score in January 2026 ??
What was Elementor's A.I Rankiteo Cyber Score in December 2025 ??
What was Elementor's A.I Rankiteo Cyber Score in November 2025 ??
What was Elementor's A.I Rankiteo Cyber Score in October 2025 ??
What was Elementor's A.I Rankiteo Cyber Score in September 2025 ??
What was Elementor's A.I Rankiteo Cyber Score in August 2025 ??
What was Elementor's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Elementor's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Elementor ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Elementor's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?