QID 730522
Date Published: 2022-06-15
QID 730522: WordPress Plugin Elementor - Reflected Cross-Site Scripting (XSS) Vulnerability
Elementor is the leading website building platform for WordPress, enabling web creators to build professional, pixel-perfect websites with an intuitive visual builder.
The Elementor Website Builder plugin for WordPress is vulnerable to DOM-based Reflected Cross-Site Scripting (XSS) vulnerability
Affected Versions:
Elementor plugin versions prior to 3.5.6.
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Elementor plugin.
Successful exploitation of this vulnerability could lead to Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS).
Solution
Customers are advised to refer Elementor Plugin to mitigate this vulnerability.
Vendor References
- Elementor Release Notes -
wordpress.org/plugins/elementor/advanced/
CVEs related to QID 730522
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Elementor |
|