CVE-2021-24257: Premium Addons for Elementor < 4.2.8 - Contributor+ Stored Cross-Site Scripting (XSS)
Published May 5, 2021
·Updated
The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Affected Software
1 affected component
Leap13 Premium Addons For Elementor Wordpress<4.2.8
Event History
May 5, 2021
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-24257.
2
What is the affected software of this vulnerability?
The affected software of this vulnerability is the 'Premium Addons for Elementor' WordPress Plugin before version 4.2.8.
3
What is the severity of CVE-2021-24257?
The severity of CVE-2021-24257 is medium with a severity value of 5.4.
4
What is the main risk of this vulnerability?
The main risk of this vulnerability is stored Cross-Site Scripting (XSS) attacks by lower-privileged users.
5
How can I fix CVE-2021-24257?
To fix CVE-2021-24257, update the 'Premium Addons for Elementor' WordPress Plugin to version 4.2.8 or higher.