cleantalk
Vulnerabilities and Security Researches

Elementor Website Builder – More than Just a Page Builder, e601fc58-97a0-4a67-8955-abf0e37e74ae

Published on
-
Research Description
Elementor Website Builder &#8211; more than just a page builder [elementor] < 2.9.8 Elementor &lt; 2.9.8 - SVG Sanitizer Bypass leading to Authenticated Stored XSS Jerome Bruandet, from NinTechNet, discovered a bypass in the SVG sanitizer, which could lead to an authenticated stored XSS issue from users with the upload_files capability.
Affected versions
max 2.9.8.
Status
vulnerable