CVE-2021-24262: WooLentor - WooCommerce Elementor Addons + Builder < 1.8.6 - Contributor+ Stored XSS
Published May 5, 2021
·Updated
The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Affected Software
1 affected component
HasThemes Woolentor - Woocommerce Elementor Addons \+ Builder Wordpress<1.8.6
Event History
May 5, 2021
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-24262.
2
What is the severity of CVE-2021-24262?
The severity of CVE-2021-24262 is medium (CVSS score 5.4).
3
What is the affected software by CVE-2021-24262?
The affected software is the “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before version 1.8.6.
4
What is the vulnerability description of CVE-2021-24262?
CVE-2021-24262 is a stored Cross-Site Scripting (XSS) vulnerability in the “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin.
5
How can I fix the vulnerability CVE-2021-24262?
To fix CVE-2021-24262, update the “WooLentor – WooCommerce Elementor Addons + Builder” plugin to version 1.8.6 or higher.