CVE-2022-4953: Elementor < 3.5.5 - Iframe Injection
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
Credit
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-4953?
CVE-2022-4953 is a vulnerability in the Elementor Website Builder WordPress plugin before version 3.5.5 that allows user-controlled URLs to be loaded into the DOM, potentially enabling the injection of rogue iframes pointing to malicious URLs.
How severe is CVE-2022-4953?
CVE-2022-4953 has a severity rating of medium with a CVSS score of 6.1.
How does CVE-2022-4953 affect Elementor Website Builder?
CVE-2022-4953 affects Elementor Website Builder before version 3.5.5, allowing user-controlled URLs to be loaded into the DOM.
How can I fix CVE-2022-4953?
To fix CVE-2022-4953, update the Elementor Website Builder WordPress plugin to version 3.5.5 or later.
Is there any additional information about CVE-2022-4953?
For more information about CVE-2022-4953, you can refer to the following resources: [GitHub commit](https://github.com/elementor/elementor/commit/292fc49e0f979bd52d838f0326d1faaebfa59f5e), [WPScan vulnerability](https://wpscan.com/vulnerability/8273357e-f9e1-44bc-8082-8faab838eda7), [Exploit DB exploit](https://www.exploit-db.com/exploits/51716).