CVE-2020-13864: XSS
Published Jun 5, 2020
·Updated
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
Affected Software
1 affected component
Elementor Elementor Page Builder Wordpress<2.9.9
Event History
Jun 5, 2020
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
Description
Frequently Asked Questions
1
What is CVE-2020-13864?
CVE-2020-13864 is a stored XSS vulnerability in the Elementor Page Builder plugin for WordPress before version 2.9.9.
2
How does CVE-2020-13864 affect WordPress?
CVE-2020-13864 allows an author user to create posts that result in a stored XSS by using a crafted payload in custom links.
3
What is the severity of CVE-2020-13864?
CVE-2020-13864 has a severity rating of medium with a CVSS score of 5.4.
4
How can I fix CVE-2020-13864 in Elementor Page Builder plugin?
To fix CVE-2020-13864, you should update the Elementor Page Builder plugin to version 2.9.9 or higher.
5
Where can I find more information about CVE-2020-13864?
More information about CVE-2020-13864 can be found at: https://www.softwaresecured.com/elementor-page-builder-stored-xss/