First published: Tue Mar 28 2023(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.48 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Unlimited Elements For Elementor | <1.5.49 | |
Unlimited Elements For Elementor | <1.5.49 |
Update to 1.5.49 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47170 has a high severity rating due to the risk of authenticated admin users being able to exploit the stored XSS vulnerability.
To mitigate CVE-2022-47170, update the Unlimited Elements for Elementor plugin to version 1.5.49 or higher.
CVE-2022-47170 affects users of the Unlimited Elements for Elementor plugin versions 1.5.48 and earlier.
CVE-2022-47170 is a stored cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts.
CVE-2022-47170 requires authenticated admin access to be exploited, limiting the potential for remote exploitation.