QID 730259
Date Published: 2021-11-16
QID 730259: WordPress Plugin Starter Templates Stored Cross-Site Scripting (XSS) Vulnerability
The Starter Templates plugin allows site owners to import prebuilt templates and blocks for various page builders, including Elementor.
CVE-2021-42360: Versions 2.7.0 and earlier of this plugin contain a vulnerability that allows Contributor-level users to completely overwrite any page on the site with malicious JavaScript.
Affected Versions:
Starter Templates plugin versions 2.7.0 or earlier.
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Starter Templates plugin.
Successful exploitation of this vulnerability may allow an attacker to steal sensitive information of the targeted user.
Solution
Customers are requested to update to Starter Templates version 2.7.1 or later to mitigate this vulnerability.
Vendor References
- Starter Templates Changelog -
wordpress.org/plugins/astra-sites/#developers
CVEs related to QID 730259
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Starter Templates Changelog |
|