First published: Fri Jun 05 2020(Updated: )
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Elementor Page Builder | <2.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13864 is a stored XSS vulnerability in the Elementor Page Builder plugin for WordPress before version 2.9.9.
CVE-2020-13864 allows an author user to create posts that result in a stored XSS by using a crafted payload in custom links.
CVE-2020-13864 has a severity rating of medium with a CVSS score of 5.4.
To fix CVE-2020-13864, you should update the Elementor Page Builder plugin to version 2.9.9 or higher.
More information about CVE-2020-13864 can be found at: https://www.softwaresecured.com/elementor-page-builder-stored-xss/