QID 730259

Date Published: 2021-11-16

QID 730259: WordPress Plugin Starter Templates Stored Cross-Site Scripting (XSS) Vulnerability

The Starter Templates plugin allows site owners to import prebuilt templates and blocks for various page builders, including Elementor.

CVE-2021-42360: Versions 2.7.0 and earlier of this plugin contain a vulnerability that allows Contributor-level users to completely overwrite any page on the site with malicious JavaScript.

Affected Versions:
Starter Templates plugin versions 2.7.0 or earlier.
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Starter Templates plugin.

Successful exploitation of this vulnerability may allow an attacker to steal sensitive information of the targeted user.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are requested to update to Starter Templates version 2.7.1 or later to mitigate this vulnerability.

    Vendor References

    CVEs related to QID 730259

    Software Advisories
    Advisory ID Software Component Link
    Starter Templates Changelog URL Logo wordpress.org/plugins/astra-sites/#developers