First published: Wed May 05 2021(Updated: )
The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Detheme Dethemekit For Elementor | <1.5.5.5 | |
Detheme Kit for Elementor | <1.5.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24270 is rated as a medium severity vulnerability due to its ability to allow stored Cross-Site Scripting (XSS).
To fix CVE-2021-24270, update the Detheme Kit for Elementor plugin to version 1.5.5.5 or higher.
CVE-2021-24270 affects users of Detheme Kit for Elementor versions prior to 1.5.5.5, including lower-privileged users such as contributors.
CVE-2021-24270 facilitates stored Cross-Site Scripting (XSS) attacks, allowing attackers to execute arbitrary scripts.
If updating is not possible, restrict user permissions to prevent lower-privileged users from accessing the vulnerable widget.