First published: Wed Jun 07 2023(Updated: )
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Website Builder WordPress | <=2.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36703 is a vulnerability in the Elementor Website Builder plugin for WordPress that allows authenticated attackers to inject arbitrary web scripts in pages via SVG image uploads.
CVE-2020-36703 has a severity rating of 5.4, which is considered medium.
Versions up to and including 2.9.7 of the Elementor Website Builder plugin for WordPress are affected by CVE-2020-36703.
An attacker with the upload_files capability can exploit CVE-2020-36703 by uploading a malicious SVG image that contains scripts to execute arbitrary code on the target website.
Yes, the Elementor Website Builder plugin for WordPress has been fixed to address the vulnerability. It is recommended to update to a version higher than 2.9.7.