Elementor Website Builder – More than Just a Page Builder, b3d8372c822b47e4e956d2254e3ee633167cd7b7
- CVE, Research URL
- Published on
- Jan 29, 2020
- Research Description
- Elementor Website Builder – more than just a page builder [elementor] < 2.7.6 Elementor Website Builder <= 2.7.5 - Stored Cross-Site Scripting The Elementor Website Builder for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.5 that makes it possible for attackers to inject arbitrary web scripts via the elementor_js_log AJAX action. This requires low-level authenticated user access to exploit.
- Affected versions
-
max 2.7.6.
- Status
-
vulnerable