CVE-2021-24259: Elementor Addon Elements < 1.11.2 - Contributor+ Stored XSS
Published May 5, 2021
·Updated
The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Affected Software
1 affected component
Webtechstreet Elementor Addon Elements Wordpress<1.11.2
Event History
May 5, 2021
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-24259.
2
What is the severity level of CVE-2021-24259?
The severity level of CVE-2021-24259 is medium with a score of 5.4.
3
What is the affected software?
The affected software is the Elementor Addon Elements WordPress Plugin before version 1.11.2.
4
What type of vulnerability is CVE-2021-24259?
CVE-2021-24259 is a stored Cross-Site Scripting (XSS) vulnerability.
5
How can the stored Cross-Site Scripting (XSS) vulnerability be exploited?
The stored Cross-Site Scripting (XSS) vulnerability can be exploited by lower-privileged users, such as contributors, via a similar method.