CVE-2021-24256: Elementor - Header, Footer & Blocks Template < 1.5.8 - Contributor+ Stored XSS
Published May 5, 2021
·Updated
The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Affected Software
1 affected component
Brainstormforce Elementor - Header\, Footer \& Blocks Template Wordpress<1.5.8
Event History
May 5, 2021
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Elementor plugin vulnerability?
The vulnerability ID for this Elementor plugin vulnerability is CVE-2021-24256.
2
What is the severity of CVE-2021-24256?
The severity of CVE-2021-24256 is medium with a CVSS score of 5.4.
3
What is the affected software?
The affected software is the “Elementor – Header, Footer & Blocks Template” WordPress Plugin version up to and excluding 1.5.8.
4
What is the vulnerability description?
The vulnerability allows lower-privileged users, such as contributors, to perform stored Cross-Site Scripting (XSS) attacks via two vulnerable widgets in the plugin.
5
Are there any patches or fixes available for this vulnerability?
Yes, patches have been released by the plugin author to address this vulnerability.