First published: Mon Jun 13 2022(Updated: )
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Website Builder WordPress | <=3.5.5 |
Update to 3.5.6 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-29455.
The title of this vulnerability is "DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin."
The description of this vulnerability is "DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions."
The Elementor Website Builder plugin version <= 3.5.5 for WordPress is affected.
The severity of this vulnerability is medium, with a severity value of 6.1.
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-79.
Yes, a patch is available for this vulnerability. Please refer to the provided references for more information.