Work at Elementor: Bug Bounty Program? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 20 Sep 2026.
Elementor is the leading website builder platform for professionals on WordPress. Elementor serves web professionals including developers, designers and marketers and boasts a new website created every 10 seconds on its platform. Elementor is an open-source, GPLv3 licensed offering its platform both as free and premium. Since launching in 2016, Elementor’s reach now extends to more than 180 countries, has more than 10,000,000 active installs, and is loved by many, as seen in over 4.5K five-star reviews it received in the WordPress repository. General Guidelines Please submit any vulnerabilities associated with our plugins to Elementor's Patchstack bounty program: * Elementor * Elementor Pro * Ally * Image Optimizer * Activity Log * Temporary Login * Site Mailer * Elementor Blocks for Gutenberg * Hello Elementor * Hello Biz * Hello Plus Vulnerability reports which will not include manual validation - for example, reports based only on results from automated tools and scanners or which describe theoretical attack vectors without proof of exploitability - will be automatically closed. Indicate steps to reproduce and verify you demonstrate a working proof of concept. Submissions without sufficient details - will be automatically closed. Please collect only the information necessary to demonstrate the vulnerability. Please only target your own accounts. DO NOT attempt to access the data of other accounts. Our program will use Bugcrowd’s Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its actual likelihood or impact. In any instance where an issue is downgraded, a detailed explanation will be provided to the researcher. Verify your target, do not attack any 3rd party supporting our services. We base all payouts on impact and will reward accordingly. Please emphasize the actual impact as part of your submission description. Rate Limiting - WAF technology is being utilized and will block high rate traffic deemed to be malicious. Stick with manual and pinpointed attack processes, don’t use mass scanning tools and avoid brute force attempts. If this occurs, discontinue your activity for a period of 24 hours. Out of Scope submissions that will indicate sufficient reasoning (why you believe it should be considered) and demonstrable impact may be considered as “In Scope” submissions (case-by-case basis). Reward Guidelines We base all payouts on impact and will reward accordingly. Please emphasize the impact as part of your submission. We are particularly interested and will consider extraordinary submissions for issues that result in full compromise of a system Priority Reward Range P1 (extraordinary submissions) Up to $5,000 P1 $2,000 - $4,000 P2 $500 - $2,000 P3 $0 - $500 P4 Points Only
Scope
8 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| https://activitylog.io/ | website | ✓ bounty | not set |
| https://developers.elementor.com/ | website | ✓ bounty | not set |
| https://elementor.careers | website | ✓ bounty | not set |
| https://go.elementor.com/ | website | ✓ bounty | not set |
| https://library.elementor.com/ | website | ✓ bounty | not set |
Show all 8 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| https://my.elementor.com/ | website | ✓ bounty | not set |
| https://send2.co/ | website | ✓ bounty | not set |
| https://translate.elementor.com/ | website | ✓ bounty | not set |