CVE-2020-36703: Elementor Website Builder <= 2.9.7 - Authenticated Stored Cross-Site Scripting
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the uploadfiles capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36703?
CVE-2020-36703 is a vulnerability in the Elementor Website Builder plugin for WordPress that allows authenticated attackers to inject arbitrary web scripts in pages via SVG image uploads.
How severe is CVE-2020-36703?
CVE-2020-36703 has a severity rating of 5.4, which is considered medium.
Which versions of Elementor Website Builder plugin for WordPress are affected by CVE-2020-36703?
Versions up to and including 2.9.7 of the Elementor Website Builder plugin for WordPress are affected by CVE-2020-36703.
How can an attacker exploit CVE-2020-36703?
An attacker with the upload_files capability can exploit CVE-2020-36703 by uploading a malicious SVG image that contains scripts to execute arbitrary code on the target website.
Are there any fixes available for CVE-2020-36703?
Yes, the Elementor Website Builder plugin for WordPress has been fixed to address the vulnerability. It is recommended to update to a version higher than 2.9.7.