CVE-2023-5381: Elementor Addon Elements <= 1.12.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.12.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-5381?
CVE-2023-5381 is a vulnerability in the Elementor Addon Elements plugin for WordPress that allows for stored cross-site scripting (XSS) attacks.
How severe is CVE-2023-5381?
CVE-2023-5381 has a severity rating of medium, with a CVSS score of 4.4.
Which version of the Elementor Addon Elements plugin is affected by CVE-2023-5381?
Versions up to and including 1.12.7 of the Elementor Addon Elements plugin for WordPress are affected by CVE-2023-5381.
How can authenticated attackers exploit CVE-2023-5381?
With administrator-level permissions, authenticated attackers can exploit CVE-2023-5381 through stored cross-site scripting (XSS) attacks via the admin settings of the plugin.
Is there a fix available for CVE-2023-5381?
Yes, updating to a version of the Elementor Addon Elements plugin for WordPress beyond 1.12.7 will mitigate the vulnerability.