CVE-2020-36171: XSS
Published Jan 6, 2021
·Updated
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
Affected Software
1 affected component
Elementor Website Builder WordPress<3.0.14
Event History
Jan 6, 2021
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Elementor Website Builder plugin issue?
The vulnerability ID for this Elementor Website Builder plugin issue is CVE-2020-36171.
2
What is the severity level of CVE-2020-36171?
CVE-2020-36171 has a severity level of medium.
3
What is the affected software for CVE-2020-36171?
The affected software for CVE-2020-36171 is Elementor Website Builder plugin for WordPress versions up to 3.0.14.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-36171?
The Common Weakness Enumeration (CWE) ID for CVE-2020-36171 is CWE-79.
5
How can I fix CVE-2020-36171?
To fix CVE-2020-36171, update the Elementor Website Builder plugin to version 3.0.14 or later.