First published: Wed Sep 16 2020(Updated: )
A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Elementor Page Builder | <=2.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-20406.
The title of the vulnerability is 'A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor'.
The severity of CVE-2020-20406 is medium with a severity value of 5.4.
Elementor Page Builder versions up to and including 2.9.2 are affected by CVE-2020-20406.
To fix the vulnerability, users should update to a version of Elementor Page Builder that is newer than 2.9.2.