First published: Mon Aug 14 2023(Updated: )
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
Credit: Miguel Santareno contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
<3.5.5 | ||
Elementor Website Builder WordPress | <3.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4953 is a vulnerability in the Elementor Website Builder WordPress plugin before version 3.5.5 that allows user-controlled URLs to be loaded into the DOM, potentially enabling the injection of rogue iframes pointing to malicious URLs.
CVE-2022-4953 has a severity rating of medium with a CVSS score of 6.1.
CVE-2022-4953 affects Elementor Website Builder before version 3.5.5, allowing user-controlled URLs to be loaded into the DOM.
To fix CVE-2022-4953, update the Elementor Website Builder WordPress plugin to version 3.5.5 or later.
For more information about CVE-2022-4953, you can refer to the following resources: [GitHub commit](https://github.com/elementor/elementor/commit/292fc49e0f979bd52d838f0326d1faaebfa59f5e), [WPScan vulnerability](https://wpscan.com/vulnerability/8273357e-f9e1-44bc-8082-8faab838eda7), [Exploit DB exploit](https://www.exploit-db.com/exploits/51716).