CVE-2022-47170: WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.48 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.48 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47170?
CVE-2022-47170 has a high severity rating due to the risk of authenticated admin users being able to exploit the stored XSS vulnerability.
How do I fix CVE-2022-47170?
To mitigate CVE-2022-47170, update the Unlimited Elements for Elementor plugin to version 1.5.49 or higher.
Who is affected by CVE-2022-47170?
CVE-2022-47170 affects users of the Unlimited Elements for Elementor plugin versions 1.5.48 and earlier.
What type of vulnerability is CVE-2022-47170?
CVE-2022-47170 is a stored cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts.
Can CVE-2022-47170 be exploited remotely?
CVE-2022-47170 requires authenticated admin access to be exploited, limiting the potential for remote exploitation.