CVE-2018-18379: XSS
Published Oct 7, 2019
·Updated
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.
Affected Software
1 affected component
Elementor Elementor Page Builder Wordpress<2.0.10
Event History
Oct 7, 2019
CVE Published
via MITRE·11:28 AM
Data Sourced
via MITRE·11:28 AM
Description
Frequently Asked Questions
1
What is CVE-2018-18379?
CVE-2018-18379 is a vulnerability in the Elementor Pro plugin for WordPress that allows for XSS attacks.
2
What is the severity of CVE-2018-18379?
The severity of CVE-2018-18379 is medium with a CVSS score of 6.1.
3
How does CVE-2018-18379 affect Elementor?
CVE-2018-18379 affects Elementor Pro plugin versions up to and including 2.0.10.
4
How do I fix CVE-2018-18379?
To fix CVE-2018-18379, update the Elementor Pro plugin to version 2.0.11 or higher.
5
Where can I find more information about CVE-2018-18379?
You can find more information about CVE-2018-18379 at the Elementor blog and the Context Information Security advisories.