CVE-2021-24263: PowerPack Addons for Elementor < 2.3.2 - Contributor+ Stored XSS
The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24263?
CVE-2021-24263 is rated as a medium severity vulnerability that allows stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2021-24263?
To fix CVE-2021-24263, update the Elementor Addons – PowerPack Addons for Elementor plugin to version 2.3.2 or higher.
Who can exploit CVE-2021-24263?
CVE-2021-24263 can be exploited by lower-privileged users, such as contributors, due to the plugin's stored XSS vulnerabilities.
What plugins are affected by CVE-2021-24263?
CVE-2021-24263 affects the Elementor Addons – PowerPack Addons for Elementor plugin versions prior to 2.3.2.
What is the impact of CVE-2021-24263?
The impact of CVE-2021-24263 includes the potential for attackers to execute arbitrary JavaScript in the context of the affected site, which can lead to session hijacking or data theft.