CVE-2021-24204: Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget
In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘titlehtmltag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘savebuilder’ request containing JavaScript in the ‘titlehtmltag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24204.
What is the severity of CVE-2021-24204?
The severity of CVE-2021-24204 is medium with a CVSS score of 5.4.
Which software is affected by CVE-2021-24204?
The Elementor Website Builder WordPress plugin before version 3.1.4 is affected by CVE-2021-24204.
What is the CWE category of CVE-2021-24204?
The CWE category of CVE-2021-24204 is CWE-79.
How can I fix CVE-2021-24204?
To fix CVE-2021-24204, update the Elementor Website Builder WordPress plugin to version 3.1.4 or later.