Elementor Website Builder – More than Just a Page Builder, CVE-2020-13865
- CVE, Research URL
- Published on
- Jun 06, 2020
- Research Description
- The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
- Affected versions
-
Min -, max 2.9.10.
- Status
-
vulnerable