First published: Wed Jan 22 2020(Updated: )
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Website Builder WordPress | <2.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7109 is a vulnerability in the Elementor Page Builder plugin for WordPress that allows the creation of new templates without proper data sanitization.
CVE-2020-7109 affects Elementor Page Builder by allowing the creation of new templates with unsanitized data, which can lead to potential security risks.
CVE-2020-7109 has a severity level of 9.8 (Critical).
To fix CVE-2020-7109, it is recommended to update Elementor Page Builder plugin to version 2.8.4 or higher.
For more information about CVE-2020-7109, you can refer to the official Elementor Page Builder plugin website: https://wordpress.org/plugins/elementor/#developers