First published: Tue Nov 23 2021(Updated: )
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Website Builder WordPress | >1.5.0<3.1.4 | |
Elementor Website Builder WordPress | >=3.2.0<3.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-24891.
The severity of the CVE-2021-24891 vulnerability is medium with a CVSS score of 6.1.
The CVE-2021-24891 vulnerability affects the Elementor Website Builder WordPress plugin by allowing a DOM Cross-Site Scripting issue due to the lack of sanitization or escape of user input.
Yes, the fix for the CVE-2021-24891 vulnerability is to update the Elementor Website Builder WordPress plugin to version 3.4.8 or later.
You can find more information about the CVE-2021-24891 vulnerability at the following references: [Reference 1](https://wpscan.com/vulnerability/fbed0daa-007d-4f91-8d87-4bca7781de2d), [Reference 2](https://www.jbelamor.com/xss-elementor-lightox.html).