https://www.wpvulnerability.net/plugin/elementor/

{“error”:0,”message”:null,”data”:{“name”:”Elementor Website Builder – More Than Just a Page Builder”,”plugin”:”elementor”,”link”:”https:\/\/wordpress.org\/plugins\/elementor\/”,”latest”:”1765208340″,”closed”:0,”vulnerability”:[{“uuid”:”a2266245064af2fdc595b4cf7122db576d8110f1328155e2764a990534189d3e”,”name”:”Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24891","name":"CVE-2021-24891","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24891","description":"[en] The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.","date":"2021-11-23"},{"id":"91a4ccc71ba9999b5d13068b3eea21567f1a8c64","name":"WordPress Elementor Website Builder plugin <= 3.1.3 – DOM Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-plugin-3-1-3-dom-cross-site-scripting-xss-vulnerability","description":"DOM Cross-Site Scripting (XSS) vulnerability discovered by Joel in WordPress Elementor Website Builder plugin (versions <= 3.1.3).","date":"2021-10-20"},{"id":"4b5da874cde9a78cfb5e08b0881127890ba1be91","name":"Elementor Website Builder <= 3.4.7 – DOM-based Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-347-dom-based-cross-site-scripting","description":"The Elementor Website Builder plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the '#elementor-action:action=lightbox&settings=' DOM in versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2021-03-23"},{"id":"fbed0daa-007d-4f91-8d87-4bca7781de2d","name":"Elementor < 3.4.8 – DOM Cross-Site-Scripting","link":"https:\/\/wpscan.com\/vulnerability\/fbed0daa-007d-4f91-8d87-4bca7781de2d","description":"The plugin does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.\r\n\r\nThe issue was initially fixed in 3.1.4, however re-introduced in 3.2.0.","date":null},{"id":"EUVD-2021-11803","name":"EUVD-2021-11803","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2021-11803","description":"Malicious code in bioql (PyPI)","date":"2025-10-03"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b3a705b74391d5f42b891be67985b5a3df01d41bcdb615d3f19bc5af183b18cf","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24202","name":"CVE-2021-24202","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24202","description":"[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes\/widgets\/heading.php) accepts a \u2018header_size\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request with this parameter set to \u2018script\u2019 and combined with a \u2018title\u2019 parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.","date":"2021-04-05"},{"id":"d0d403c5180c8f5da1d5c2be2df333af0a982167","name":"Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via header_size","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-313-authenticated-contributor-stored-cross-site-scripting-via-header-size","description":"In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes\/widgets\/heading.php) accepts a \u2018header_size\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request with this parameter set to \u2018script\u2019 and combined with a \u2018title\u2019 parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.","date":"2021-03-17"},{"id":"b72bd13d-c8e2-4347-b009-542fc0fe21bb","name":"Elementor < 3.1.2 – Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget","link":"https:\/\/wpscan.com\/vulnerability\/b72bd13d-c8e2-4347-b009-542fc0fe21bb","description":"In the plugin, the heading widget (includes\/widgets\/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘title’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"ba82235800e006a97723423fb22788d428780248328950c474bd22f827cdf47f","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24203","name":"CVE-2021-24203","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24203","description":"[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes\/widgets\/divider.php) accepts an \u2018html_tag\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request with this parameter set to \u2018script\u2019 and combined with a \u2018text\u2019 parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.","date":"2021-04-05"},{"id":"6f842d2261bf1528c593c634b0804d49834cd2fd","name":"Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-313-authenticated-contributor-stored-cross-site-scripting-via-html-tag-2","description":"In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes\/widgets\/divider.php) accepts an \u2018html_tag\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request with this parameter set to \u2018script\u2019 and combined with a \u2018text\u2019 parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.","date":"2021-03-17"},{"id":"aa152ad0-5b3d-4d1f-88f4-6899a546e72e","name":"Elementor < 3.1.2 – Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget","link":"https:\/\/wpscan.com\/vulnerability\/aa152ad0-5b3d-4d1f-88f4-6899a546e72e","description":"In the plugin, the divider widget (includes\/widgets\/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘text’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f476f8dcfe6b8d14a11a0ee4f99304f5eff5026329266f933644505c5b3820e3","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24204","name":"CVE-2021-24204","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24204","description":"[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes\/widgets\/accordion.php) accepts a \u2018title_html_tag\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request containing JavaScript in the \u2018title_html_tag\u2019 parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":"2021-04-05"},{"id":"2bdf110c8d06109c123456cf3d0a39ddc5723892","name":"Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_html_tag","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-313-authenticated-contributor-stored-cross-site-scripting-via-title-html-tag","description":"In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes\/widgets\/accordion.php) accepts a \u2018title_html_tag\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request containing JavaScript in the \u2018title_html_tag\u2019 parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":"2021-03-17"},{"id":"772e172f-c8b4-4a6a-9eb9-9663295cfedf","name":"Elementor < 3.1.2 – Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget","link":"https:\/\/wpscan.com\/vulnerability\/772e172f-c8b4-4a6a-9eb9-9663295cfedf","description":"In the plugin, the accordion widget (includes\/widgets\/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"22e74f5a532517a079ef5df6d1c3f857bb5d5377cc57ef46ce68bfac201baaf1","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24205","name":"CVE-2021-24205","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24205","description":"[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes\/widgets\/icon-box.php) accepts a \u2018title_size\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request containing JavaScript in the \u2018title_size\u2019 parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":"2021-04-05"},{"id":"19772699edd5552e95885ea1841e5917509e1e86","name":"Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_size Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-313-authenticated-contributor-stored-cross-site-scripting-via-title-size-parameter","description":"In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes\/widgets\/icon-box.php) accepts a \u2018title_size\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request containing JavaScript in the \u2018title_size\u2019 parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":"2021-03-17"},{"id":"ef23df6d-e265-44f6-bb94-1005b16d34d9","name":"Elementor < 3.1.2 – Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget","link":"https:\/\/wpscan.com\/vulnerability\/ef23df6d-e265-44f6-bb94-1005b16d34d9","description":"In the plugin, the icon box widget (includes\/widgets\/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"23c0ec3ffb203a30cd175be6e92815f13f24adf79777d3d0ac39606e98c8db93","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24206","name":"CVE-2021-24206","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24206","description":"[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes\/widgets\/image-box.php) accepts a \u2018title_size\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request containing JavaScript in the \u2018title_size\u2019 parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":"2021-04-05"},{"id":"c01101f0470e85520c7b7b3b542124bc5619edd6","name":"Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_size","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-313-authenticated-contributor-stored-cross-site-scripting-via-title-size","description":"In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes\/widgets\/image-box.php) accepts a \u2018title_size\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request containing JavaScript in the \u2018title_size\u2019 parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":"2021-03-17"},{"id":"2f66efd9-7d55-4f33-9109-3cb583a0c309","name":"Elementor < 3.1.2 – Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget","link":"https:\/\/wpscan.com\/vulnerability\/2f66efd9-7d55-4f33-9109-3cb583a0c309","description":"In the plugin, the image box widget (includes\/widgets\/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"30fdf526f9d9eaac3fb787834483f6842ae66d67105509dd98e5a3250b6b053b","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24201","name":"CVE-2021-24201","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24201","description":"[en] In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes\/elements\/column.php) accepts an \u2018html_tag\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request containing JavaScript in the \u2018html_tag\u2019 parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":"2021-04-05"},{"id":"c11a586c56bde45c2180986e3fa6a8f860bd06d9","name":"Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-313-authenticated-contributor-stored-cross-site-scripting-via-html-tag","description":"In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes\/elements\/column.php) accepts an \u2018html_tag\u2019 parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified \u2018save_builder\u2019 request containing JavaScript in the \u2018html_tag\u2019 parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":"2021-03-17"},{"id":"9647f516-b130-4cc8-85fb-2e69b034ced0","name":"Elementor < 3.1.2 – Authenticated Stored Cross-Site Scripting (XSS) in Column Element","link":"https:\/\/wpscan.com\/vulnerability\/9647f516-b130-4cc8-85fb-2e69b034ced0","description":"In the plugin, the column element (includes\/elements\/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"713b199dcfd717eebea47bd19d541e9fbf192bc3781962a14b5ddd033037cb37","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.0.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36171","name":"CVE-2020-36171","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36171","description":"[en] The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.","date":"2021-01-06"},{"id":"011203948e040402a57a4ab2a79bfe3183e03869","name":"WordPress Elementor Website Builder plugin <= 3.0.13 – Unrestricted SVG Uploads vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-plugin-3-0-13-unrestricted-svg-uploads-vulnerability","description":"Unrestricted SVG Uploads vulnerability found in WordPress Elementor Website Builder plugin (versions <= 3.0.13).","date":"2020-11-25"},{"id":"82a9554a86bec9ad8d5a6d8d7838ede761385516","name":"Elementor Website Builder <= 3.0.13 – Unrestricted SVG Uploads","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-3013-unrestricted-svg-uploads","description":"The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized malicious SVG file uploads in versions up to, and including, 3.0.13. This is due to improper restrictions on allowing SVG file uploads. This makes it possible for authenticated attackers with post editor access to upload SVG files that could contain malicious content such as web scripts.","date":"2020-11-25"},{"id":"5c5f44e1-c00b-4a90-a581-ef06765b7f66","name":"Elementor < 3.0.14 – SVG Upload Allowed by Default","link":"https:\/\/wpscan.com\/vulnerability\/5c5f44e1-c00b-4a90-a581-ef06765b7f66","description":"The plugin allowed SVG files to be uploaded by default, which might lead to security issues, such as Cross-Site Scripting","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"cf7e2ea0cf9c6cf29e1d16e1d81285900dba686f1ebf266cd6bccce8194e1774","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-20406","name":"CVE-2020-20406","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-20406","description":"[en] A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.","date":"2020-09-16"},{"id":"dd871091bdfc007a6cda405b07496bb09403da45","name":"Elementor Website Builder <= 2.9.2 – Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-292-stored-cross-site-scripting","description":"A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.","date":"2020-02-26"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"6515725f13fd232d44007fb930da9b1afd02b5ed22b43e49f09e9f4bb8bc21dc","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-15020","name":"CVE-2020-15020","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-15020","description":"[en] An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.","date":"2020-08-31"},{"id":"868542236e82eed67beca6b723b1d3f80792ed9d","name":"WordPress Elementor Website Builder plugin <= 2.9.13 – Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-plugin-2-9-13-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Th3 Hidd3n 0n3 in WordPress Elementor Website Builder plugin (versions <= 2.9.13).","date":"2020-09-02"},{"id":"59b0e1e7fc8127aa63729a58ee963aac83c7ee03","name":"Elementor Website Builder <= 2.9.13 – Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-2913-authenticated-stored-cross-site-scripting","description":"An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.","date":"2020-07-07"},{"id":"7dfde62f-f167-403b-8b23-f4ac845ac04d","name":"Elementor < 2.9.14 – Authenticated Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/7dfde62f-f167-403b-8b23-f4ac845ac04d","description":"The template name is not properly sanitised when output back, leading to a stored XSS issue.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"161158813ec5e98b4b1189a812e756c7b52db63c36f21e783d9312668bd9cc49","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-20634","name":"CVE-2020-20634","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-20634","description":"[en] Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.","date":"2020-08-21"},{"id":"b64cae1df12bd4bf1c7cb1a4ceb33cb929c3edb0","name":"Elementor Website Builder <= 2.9.5 – Authorization Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-295-authorization-bypass","description":"Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.","date":"2020-03-31"},{"id":"7120f212-0c04-4c41-b6a8-32a380c0c25d","name":"Elementor Page Builder < 2.9.6 – Authenticated Safe Mode Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/7120f212-0c04-4c41-b6a8-32a380c0c25d","description":"The Elementor WordPress plugin could allow an authenticated user to enable Safe Mode. This could allow the user to then disable plugins, which could include security plugins, which would weaken the overall security of the site.","date":null}],"impact":[]},{"uuid":"8dabcef5e3019facbf02788001b8c8c562bee74c7bac6483070b3ecfbf0b0561","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-13864","name":"CVE-2020-13864","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-13864","description":"[en] The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.","date":"2020-06-05"},{"id":"4d17a6c4a7550b5e7b68b6e34369d47a93afa152","name":"Elementor Website Builder <= 2.9.8 – Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-298-stored-cross-site-scripting","description":"The Elementor Website Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.","date":"2020-06-05"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"15a0a4d36d836ccbad6482f3464ce6149a86bdec4354d7ddd78a43b59d6176ba","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-13865","name":"CVE-2020-13865","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-13865","description":"[en] The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.","date":"2020-06-05"},{"id":"7aba90a90cc0657502427a5c08af9e87772fb8b1","name":"Elementor Website Builder <= 2.9.8 – Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-298-stored-cross-site-scripting-2","description":"The Elementor Website Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.","date":"2020-06-05"},{"id":"31659b56-2046-4be8-887f-a016da138595","name":"Elementor Page Builder < 2.9.10 – Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/31659b56-2046-4be8-887f-a016da138595","description":"The Elementor Page Builder plugin is susceptible to stored XSS. An author user can create custom links containing XSS payloads or apply custom attributes to widgets which results in XSS.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"842686efb44a337b8c45e010fb6cba6f4c95867beba3a23e13c6fd0bc27aa343","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.8.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-8426","name":"CVE-2020-8426","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-8426","description":"[en] The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.","date":"2020-01-28"},{"id":"f78fbbddc877693b2dcee163186f51767097b3d8","name":"WordPress Elementor Page Builder plugin <= 2.8.4 – Authenticated Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-page-builder-plugin-2-8-4-authenticated-reflected-cross-site-scripting-xss-vulnerability","description":"Authenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Impenetrable in WordPress Elementor Page Builder plugin (versions <= 2.8.4).","date":"2020-01-30"},{"id":"34a47e9df2abddd934ac3fc062bfcc4c2decfe42","name":"Elementor Website Builder <= 2.8.4 – Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-284-reflected-cross-site-scripting","description":"The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.","date":"2020-01-29"},{"id":"e1422824-adba-4d7c-a7f3-c0a6b3ab0232","name":"Elementor Page Builder < 2.8.5 – Authenticated Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/e1422824-adba-4d7c-a7f3-c0a6b3ab0232","description":"The Elementor Website Builder WordPress plugin was affected by an Authenticated Reflected XSS security vulnerability.","date":null}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"96db4938011b5f664fc806c5ce2e96dc0d2f72dd8f973da69f4676a55f17b0cb","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.8.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-7109","name":"CVE-2020-7109","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-7109","description":"[en] The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.","date":"2020-01-22"},{"id":"7c446cd3dda8ac8e98418d98f24dc7785d9a9ed0","name":"Elementor Website Builder <= 2.8.3 – Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-283-cross-site-scripting","description":"The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.","date":"2020-01-19"},{"id":"6503bdfa-013a-4172-8e3f-ea99444f1eca","name":"Elementor Page Builder < 2.8.4 – Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/6503bdfa-013a-4172-8e3f-ea99444f1eca","description":"Elementor Page Builder before 2.8.4 does not sanitise data when creating a new template, which could lead to Cross-Site Scripting issues","date":null}],"impact":[]},{"uuid":"0c664276e0f71d2d1b0149c18a07765e2b18c61c87e9cfacb976703d2dd893de","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 1.8.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-18596","name":"CVE-2017-18596","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-18596","description":"[en] The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.","date":"2019-09-10"},{"id":"9e6f008b79103d76a59252eca07635e5014e2df7","name":"Elementor Website Builder = 3.6.0 – <= 3.6.2","description":null,"operator":{"min_version":"3.6.0","min_operator":"ge","max_version":"3.6.2","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1329","name":"CVE-2022-1329","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1329","description":"[en] The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~\/core\/app\/modules\/onboarding\/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.","date":"2022-04-19"},{"id":"bcbe0ff1733112b19b16494bd5c9a591ade9ebfa","name":"WordPress Elementor Website Builder plugin <= 3.6.2 – Arbitrary File Upload vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-plugin-3-6-2-arbitrary-file-upload-vulnerability","description":"Arbitrary File Upload vulnerability discovered by Ramuel Gall (Wordfence) in WordPress Elementor Website Builder plugin (versions <= 3.6.2).","date":"2022-04-13"},{"id":"be0c2e16d7ed33f8e3fa2242d6d0996afa48485b","name":"Elementor Website Builder 3.6.0 – 3.6.2 – Missing Authorization to Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-360-362-missing-authorization-to-remote-code-execution","description":"The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~\/core\/app\/modules\/onboarding\/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.","date":"2022-04-13"},{"id":"df62d170-c7d1-43a4-b6dc-20512934c33e","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/df62d170-c7d1-43a4-b6dc-20512934c33e","description":null,"date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"c9c9e938ba168a517e3065d664f8f2fa89e08c1c3f8ccaf04cab17451ff58094","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"676b23d1f432ff7103569a2a1514706c31251c73","name":"WordPress Elementor Website Builder plugin <= 3.1.1 – Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-plugin-3-1-1-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities","description":"Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities found by WordFence in WordPress Elementor Website Builder plugin (versions <= 3.1.1).","date":"2021-03-17"}],"impact":[]},{"uuid":"97c7bb986b1b9ea5b71f2a55a7b499e95ee23d0ca00ca6cc55380248e826b04d","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.7.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2b309eb4fbc8e044299af47372cce5292f0d76cb","name":"WordPress Elementor Page Builder plugin <= 2.7.5 – Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-page-builder-plugin-2-7-5-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Marc Alexandre Montpas (Sucuri) in WordPress Elementor Page Builder plugin (versions <= 2.7.5).","date":"2020-01-29"}],"impact":[]},{"uuid":"eb935a36f3cece4c35f4e7efab4d5c8e6b59692bf9d07b6d212c4cf1fc2c1c70","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 1.8.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e8c4dc29b2e64bf91692851dc73f966455e4fa5b","name":"WordPress Elementor Page Builder <=1.7.12 – Authenticated Unrestricted Editing vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-page-builder-1-7-12-authenticated-unrestricted-editing-vulnerability","description":"Authenticated Unrestricted Editing vulnerability found by James Golovich in WordPress Elementor Page Builder (version <=1.7.12).","date":"2017-12-02"}],"impact":[]},{"uuid":"5d36808e7f7171ed456cb6a2d033c7b3ac6bd78777a1a66b6f38aaacf6b277ff","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 1.8.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5d5b85bd5e9c8387b8a62b7638717ccbad62cc8a","name":"WordPress Elementor Page Builder <=1.8.7 – Potential Privilege Escalation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-page-builder-1-8-7-potential-privilege-escalation-vulnerability","description":"Potential Privilege Escalation vulnerability found in WordPress Elementor Page Builder (versions <=1.8.7).","date":"2017-12-02"}],"impact":[]},{"uuid":"a45f367b7615c5788190616c8f62d77bc61c62fd6dd66d6cc1a836bc117cfdad","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-29455","name":"CVE-2022-29455","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-29455","description":"[en] DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.","date":"2022-06-13"},{"id":"40d48f459d429f806ddcee0d812fd2569ac3bd2d","name":"WordPress Elementor plugin <= 3.5.5 – Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-5-5-unauthenticated-dom-based-reflected-cross-site-scripting-xss-vulnerability","description":"Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability discovered by Rotem Bar (Patchstack Alliance) in WordPress Elementor plugin (versions <= 3.5.5).\nUpdate the WordPress Elementor plugin to the latest available version (at least 3.5.6).","date":"2022-06-13"},{"id":"046c18f61e4dbb60c45fc98b46b7775e1755c954","name":"Elementor Website Builder <= 3.5.5 – Unauthenticated DOM-based Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-355-unauthenticated-dom-based-reflected-cross-site-scripting","description":"The Elementor Website Builder plugin for WordPress is vulnerable to Unauthenticated DOM-based Reflected Cross-Site Scripting via the \u2018videoType\u2019 and 'onError' parameter in the lightbox module in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2022-06-13"},{"id":"9758570b-4729-4eef-ad52-b6e922f536d6","name":"Elementor < 3.5.6 – DOM Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/9758570b-4729-4eef-ad52-b6e922f536d6","description":"The plugin does not sanitise and escape user input appended to the DOM via malicious Lightbox settings, resulting in a DOM Cross-Site Scripting issue","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"n","i":"l","a":"n","score":"4.7","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"a82722c8e9d31bdf6d1edf1ed068f32f356abe6032c4b31d662696dc231ebc65","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0dae9b941890def7a8bbbdf28e93159a1ae10b31","name":"Elementor Website Builder <= 2.9.7 – Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-297-authenticated-stored-cross-site-scripting","description":"The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.","date":"2020-04-21"}],"impact":[]},{"uuid":"9ebdb28ccadd367badcaf481606ca6ada83ce2988a87e5e62eac4b29bf30b69b","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.7.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b3d8372c822b47e4e956d2254e3ee633167cd7b7","name":"Elementor Website Builder <= 2.7.5 – Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-275-stored-cross-site-scripting","description":"The Elementor Website Builder for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.5 that makes it possible for attackers to inject arbitrary web scripts via the elementor_js_log AJAX action. This requires low-level authenticated user access to exploit.","date":"2020-01-29"}],"impact":[]},{"uuid":"a14088cbcb5662250b5d8901908d00e2d2868770c333e039f81a51aa7fea9be7","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.7.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-7055","name":"CVE-2020-7055","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-7055","description":"[en] An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.","date":"2020-04-22"},{"id":"a4a9071d9e198a52c637e4c9073043d7e41269ad","name":"Elementor Website Builder <= 2.7.4 – Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-274-arbitrary-file-upload","description":"The Elementor Website Builder plugin for WordPress is vulnerable to arbitrary file upload by subscriber level users and above due to missing authorization on the Import Templates function, which makes it possible for attackers to gain remote code execution. This affects versions up to 2.7.5.","date":"2019-10-28"},{"id":"3b7e04de-e23f-4cf9-a9bf-2cf4cbc8c538","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/3b7e04de-e23f-4cf9-a9bf-2cf4cbc8c538","description":null,"date":null}],"impact":{"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}]}},{"uuid":"4fcbb526371b28a745d0bf08e5d9d332175b3485bacb94828755ad058889d6df","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e601fc58-97a0-4a67-8955-abf0e37e74ae","name":"Elementor < 2.9.8 – SVG Sanitizer Bypass leading to Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/e601fc58-97a0-4a67-8955-abf0e37e74ae","description":"Jerome Bruandet, from NinTechNet, discovered a bypass in the SVG sanitizer, which could lead to an authenticated stored XSS issue from users with the upload_files capability.","date":null}],"impact":[]},{"uuid":"b0c9f10b2776ffd315592a5036a6d8ed845f57dc14f07ecacaa20672ce84a052","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.7.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2bcf7eb7-cddb-4d6a-8789-43dd3dff4dcf","name":"Elementor Page Builder < 2.7.6 – Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/2bcf7eb7-cddb-4d6a-8789-43dd3dff4dcf","description":"According to the original researcher, "A successful attack results in malicious scripts being injected on the plugin’s System Info page"","date":null}],"impact":[]},{"uuid":"565068cf2e56373b8619f790e45c2f631d85f442000ae908a752241434f2b66b","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.12.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4518bf0837d226dd726dd761c59a50f3e2c38ebe","name":"Elementor <= 3.12.1 – Authenticated(Administrator+) SQL Injection via 'replace_urls'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3121-authenticatedadministrator-sql-injection-via-replace-urls","description":"The Elementor plugin for WordPress is vulnerable to blind SQL Injection via the 'replace_urls' functionality in versions up to, and including, 3.12.1 due to insufficient escaping on the user supplied 'old' and 'new' parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator-level permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2023-04-24"}],"impact":[]},{"uuid":"224ebf13e69c3784eef500bbf7dc2d5fbb220736818f8672a6e947741a7007ba","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.12.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bd137d81cc782d2d6962a30f332177bad11ea49f","name":"WordPress Elementor Website Builder Plugin <= 3.12.1 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-12-1-auth-sql-injection-sqli-vulnerability","description":"Update the Elementor plugin to the latest available version (at least 3.12.2).\nAn unknown person discovered and reported this SQL Injection vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 3.12.2.","date":"2023-04-24"}],"impact":[]},{"uuid":"8a6080fb9ce29ee09ef398e3e7a2e883df0b0ff235860753b7250b427dc45e56","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.13.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"077686be39e7fb56734cd28719ab2be7fa68cca7","name":"Elementor <= 3.13.1 – Missing Authorization to Settings Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3131-missing-authorization-to-settings-update","description":"The Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the register_as_beta_tester(), ajax_enable_safe_mode(), ajax_get_category_items(), and ajax_re_migrate_globals() functions called via AJAX actions in versions up to, and including, 3.13.1. This makes it possible for authenticated attackers with minimal permissions such as subscribers to perform many actions such as registering the site for beta testing, enabling safe mode, remigrating globals and retrieving category items.","date":"2023-05-12"}],"impact":[]},{"uuid":"cbb5cf9fe805168cbc2e6e5ac646f9e84186555dd1fe0f8e2dbbdf24cc40bc63","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.13.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1b2426837206711ede152accbdd40b8945b7b899","name":"WordPress Elementor Website Builder Plugin <= 3.13.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-13-1-missing-authorization-to-settings-update-vulnerability","description":"Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.13.2).\nAn unknown person discovered and reported this Broken Access Control vulnerability in WordPress Elementor Website Builder Plugin. This vulnerability has been fixed in version 3.13.2.","date":"2023-05-12"}],"impact":[]},{"uuid":"ee97a666444beaea39e3977e30bdcb1d3cfced5b8da9f256019589336a595278","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.13.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-33922","name":"CVE-2023-33922","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-33922","description":"[en] Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n\/a through 3.13.2.","date":"2024-06-11"},{"id":"3dc9b1189440446c6b95206fdb45ecdd7921c4a7","name":"WordPress Elementor Website Builder Plugin <= 3.13.2 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-13-2-broken-access-control-vulnerability","description":"Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.13.3).\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Elementor Website Builder Plugin. This vulnerability has been fixed in version 3.13.3.","date":"2023-05-24"},{"id":"c2ded005c95b1cc710bf7bc6a82478d9a706d4e4","name":"Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3133-authenticatedcontributor-arbitrary-post-type-creation-via-save-item","description":"The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template \"save_item\" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or above, to create templates with an arbitrary post type, potentially allowing the exploitation of other plugins that depend on custom post types.","date":"2023-05-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"169d89668413192f8095864d6df181ca0e792d6287c3ecf3775252b8099ce8a4","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.12.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-0329","name":"CVE-2023-0329","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-0329","description":"[en] The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.","date":"2023-05-30"},{"id":"a875836d-77f4-4306-b275-2b60efff1493","name":"Elementor Website Builder < 3.12.2 – Admin+ SQLi","link":"https:\/\/wpscan.com\/vulnerability\/a875836d-77f4-4306-b275-2b60efff1493","description":"The plugin does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.","date":null}],"impact":{"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"4535b31a5a17d2df15fc0f9f7c6cb293025e273ac94c0701cb04390de9fc6897","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 2.9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36703","name":"CVE-2020-36703","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36703","description":"[en] The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.","date":"2023-06-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"8c966dbbfd7b6386451a9018dcf7bf272465b169b6a855028cd6b3048ed65b11","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-4953","name":"CVE-2022-4953","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4953","description":"[en] The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.","date":"2023-08-14"},{"id":"2db054b7ed90b516f3aa4936800bb207066af35c","name":"Elementor <= 3.5.4 – DOM-Based iFrame Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-354-dom-based-iframe-injection","description":"The Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018settings\u2019 hash parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary iframes in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-07-19"},{"id":"8273357e-f9e1-44bc-8082-8faab838eda7","name":"Elementor < 3.5.5 – Iframe Injection","link":"https:\/\/wpscan.com\/vulnerability\/8273357e-f9e1-44bc-8082-8faab838eda7","description":"The plugin does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.","date":null}],"impact":{"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"\”, and \”&\” that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.”}]}},{“uuid”:”977c576cb23f9e1e80d061aa8cbf829891a4337a483d082eccb34a137f0f880e”,”name”:”Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.13.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0b68091c-6a05-4f81-a718-6ec139df2e96","name":"Elementor Website Builder < 3.13.2 – Missing Authorization","link":"https:\/\/wpscan.com\/vulnerability\/0b68091c-6a05-4f81-a718-6ec139df2e96","description":"The plugin does not check user capabilities on several functions, allowing authenticated attackers with a low amount of privilege (such as Subscribers) to perform actions that should only be available to users with higher privileges.","date":null}],"impact":[]},{"uuid":"78bb2a20025db2d7b20657b4ceb36e52db2b020cd9259ce56181b217a8888680","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.16.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.16.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47505","name":"CVE-2023-47505","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47505","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n\/a through 3.16.4.","date":"2023-11-30"},{"id":"ed5ef4b7beaefd5cd339cd52d5531cb9e53dcf5a","name":"WordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-16-4-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.16.5).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.16.5.","date":"2023-11-08"},{"id":"c61fa5892bc239af689af74c510feb91fb2c9eee","name":"Elementor Website Builder <= 3.16.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-3164-authenticated-contributor-stored-cross-site-scripting-via-get-inline-svg","description":"The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the get_inline_svg() function in versions up to, and including, 3.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-11-08"},{"id":"62b53acf-6551-4ea7-8727-039a3c9ba7ce","name":"Elementor Website Builder < 3.16.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()","link":"https:\/\/wpscan.com\/vulnerability\/62b53acf-6551-4ea7-8727-039a3c9ba7ce","description":"The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the get_inline_svg() function in versions up to, and including, 3.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f93b3ae02fc1b304cc8b17874f8bda3eb8d029491c4a7d81e37b93907834a6b5","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.16.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.16.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47504","name":"CVE-2023-47504","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47504","description":"[en] Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n\/a through 3.16.4.","date":"2024-04-24"},{"id":"8faf4064cf4a7c2b273ec896d4895b951b6d2be0","name":"WordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-16-4-contributor-arbitrary-attachment-read-vulnerability","description":"Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.16.5).\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Elementor Website Builder Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.16.5.","date":"2023-11-08"},{"id":"a632d94debbda8d1408e3a3f14f69e2d68cc5504","name":"Elementor Website Builder <= 3.16.4 – Missing Authorization to Arbitrary Attachment Read","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-3164-missing-authorization-to-arbitrary-attachment-read","description":"The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_inline_svg function in all versions up to, and including, 3.16.4. This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary attachment files.","date":"2023-11-08"},{"id":"e60f0f7e-4c3b-4107-803a-8e03526859ed","name":"Elementor Website Builder < 3.16.5 – Missing Authorization to Arbitrary Attachment Read","link":"https:\/\/wpscan.com\/vulnerability\/e60f0f7e-4c3b-4107-803a-8e03526859ed","description":"The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_inline_svg function in all versions up to, and including, 3.16.4. This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary attachment files.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}]}},{"uuid":"91e86afb6dd89d885af26797c11a1dc47253f4866ef5a0a6e560809ba7386eb0","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.18.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.18.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-48777","name":"CVE-2023-48777","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-48777","description":"[en] Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.","date":"2024-03-26"},{"id":"10e9e421a7ca42866983a73a3f36716fda02af58","name":"WordPress Elementor Website Builder Plugin 3.3.0-3.18.1 is vulnerable to Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-18-0-arbitrary-file-upload-vulnerability","description":"Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.18.2).\nH\u1ed3ng Qu\u00e2n (luk6785 at VNPT-VCI) discovered and reported this Arbitrary File Upload vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 3.18.2.","date":"2023-12-06"},{"id":"4ea056595dd555317d7ef8bf228762207a69ff60","name":"Elementor <= 3.18.1 – Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3180-authenticatedcontributor-arbitrary-file-upload-to-remote-code-execution-via-template-import","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Remote Code Execution via file upload in all versions up to and including 3.18.1 via the template import functionality. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files and execute code on the server.","date":"2023-12-06"},{"id":"a6b3b14c-f06b-4506-9b88-854f155ebca9","name":"Elementor < 3.18.2 – Contributor+ Arbitrary File Upload to RCE via Template Import","link":"https:\/\/wpscan.com\/vulnerability\/a6b3b14c-f06b-4506-9b88-854f155ebca9","description":"The plugin is vulnerable to Remote Code Execution via file upload via the template import functionality, allowing authenticated attackers, with contributor-level access and above, to upload files and execute code on the server.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.9","severity":"c","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}]}},{"uuid":"773f797bd65062faaedf235258c4368326fbb809cc88f5349bfcee32eec6a28c","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.19.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.19.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0506","name":"CVE-2024-0506","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0506","description":"[en] The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-02-20"},{"id":"422fcbdfe976a1c5ca9c77d202584798191d0245","name":"Elementor Website Builder \u2013 More than Just a Page Builder <= 3.18.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-more-than-just-a-page-builder-3183-authenticated-contributor-stored-cross-site-scripting-via-get-image-alt","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-02-07"},{"id":"017a588e2427efd475983fab14f6ad9cb986f13d","name":"WordPress Elementor Website Builder Plugin <= 3.18.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-18-3-authenticated-stored-cross-site-scripting-via-get-image-alt-vulnerability","description":"Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.19.0).\nwesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.19.0.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"57af46d9-9a26-4085-9829-e0add7893332","name":"Elementor Website Builder – More than Just a Page Builder < 3.19.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt","link":"https:\/\/wpscan.com\/vulnerability\/57af46d9-9a26-4085-9829-e0add7893332","description":"The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"\”, and \”&\” that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.”}]}},{“uuid”:”47c75711c3bdaef05779f437bba2070db40cfe4a0f0831a8518dd402b9a62a3f”,”name”:”Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.19.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.19.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-24934","name":"CVE-2024-24934","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-24934","description":"[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n\/a through 3.19.0.","date":"2024-05-17"},{"id":"4f88cf618eb50fde2045401677b6227724f0918b","name":"Elementor <= 3.19.0 – Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3190-authenticatedcontributor-arbitrary-file-deletion-and-phar-deserialization","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary file deletions and PHAR deserialization in version up to, and including 3.19.0. This is due to the plugin not providing sufficient path validation on the 'tmp_name' parameter . This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files and inject PHP Objects through the use of a phar wrapper, both of which can lead to remote code execution.","date":"2024-02-07"},{"id":"1a9bda076ad23f94bcf2a0583cf20be6867a1df2","name":"WordPress Elementor Website Builder Plugin <= 3.19.0 is vulnerable to Arbitrary File Deletion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-19-0-arbitrary-file-deletion-and-phar-deserialization-vulnerability","description":"Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.19.1).\nRhynorater (Justin Gardner) discovered and reported this Arbitrary File Deletion vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to delete files from your website. If core files are deleted from your website, it could cause your site to break and stop functioning. This vulnerability has been fixed in version 3.19.1.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"4d7dfcc6-8c32-4e0d-b3bb-7e2685916e2b","name":"Elementor < 3.19.1 – Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization","link":"https:\/\/wpscan.com\/vulnerability\/4d7dfcc6-8c32-4e0d-b3bb-7e2685916e2b","description":"The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary file deletions and PHAR deserialization in version up to, and including 3.19.0. This is due to the plugin not providing sufficient path validation on the 'tmp_name' parameter . This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files and inject PHP Objects through the use of a phar wrapper, both of which can lead to remote code execution.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"l","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"8.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"a4aec2b217e4ce34d7ff6cb3b751e96c58c86f0931a7f90ece9d3d93cc3f3dec","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.20.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.20.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2117","name":"CVE-2024-2117","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2117","description":"[en] The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"e9948b6d395e4aa46ed41c49c48786f425b9866f","name":"Elementor Website Builder \u2013 More than Just a Page Builder <= 3.20.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-more-than-just-a-page-builder-3202-authenticated-contributor-dom-based-stored-cross-site-scripting-via-path-widget","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-26"},{"id":"9234137714aa57661895b115d963393cde0647ab","name":"WordPress Elementor Website Builder Plugin <= 3.20.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-20-2-auth-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.20.3).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.20.3.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"22e8d017-79f5-40c8-8a2c-e0ee42ba80c8","name":"Elementor Website Builder < 3.20.3 – Contributor+ DOM Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/22e8d017-79f5-40c8-8a2c-e0ee42ba80c8","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget due to insufficient output escaping on user supplied attributes, allowingnauthenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d01d6af76741a8aab3bcf94c46da9adfa428b66461bc1703224ba2bf4b4e2f2c","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.22.0-beta2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.22.0-beta2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4619","name":"CVE-2024-4619","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4619","description":"[en] The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the \u2018hover_animation\u2019 parameter in versions up to, and including, 3.21.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-21"},{"id":"8a5ffabf355d81076c9903143ba6083e21fb2ccc","name":"WordPress Elementor Website Builder Plugin <= 3.21.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-plugin-3-21-4-authenticated-contributor-dom-based-stored-cross-site-scripting-vulnerability","description":"

WordPress Elementor Website Builder Plugin <= 3.21.4 is vulnerable to Cross Site Scripting (XSS)

Software: Elementor Website Builder

Link: https:\/\/wordpress.org\/plugins\/elementor\/#developers

Affected Version <= 3.21.4

Fixed in version 3.22.0-beta2 “,”date”:”2024-05-21″},{“id”:”6abf7072925ed20f961490a6319a9d2c4f7af3a8″,”name”:”Elementor Website Builder \u2013 More than Just a Page Builder <= 3.21.5 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-more-than-just-a-page-builder-3214-authenticated-contributor-dom-based-stored-cross-site-scripting","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the \u2018hover_animation\u2019 parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"96ebb33f5eca9686f88b15dcb7c96601ae40173f1bb24fab959c735e276e142c","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.22.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.22.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37437","name":"CVE-2024-37437","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37437","description":"[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Cross-Site Scripting (XSS), Stored XSS.This issue affects Elementor Website Builder: from n\/a through 3.22.1.","date":"2024-07-09"},{"id":"e2d353f877618cf93af1e1ed3746ef007c9dae89","name":"WordPress Elementor Website Builder Plugin <= 3.22.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-more-than-just-a-page-builder-plugin-3-22-1-arbitrary-file-download-vulnerability","description":"

WordPress Elementor Website Builder Plugin <= 3.22.1 is vulnerable to Cross Site Scripting (XSS)

Software: Elementor Website Builder

Link: https:\/\/wordpress.org\/plugins\/elementor\/#developers

Affected Version <= 3.22.1

Fixed in version 3.22.2 “,”date”:”2024-06-28″},{“id”:”a8db0b6607c1aeacaa8f101d491b2430e03420ad”,”name”:”Elementor Website Builder <= 3.22.1 – Authenticated (Contributor+) Arbitrary SVG Download","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-3221-authenticated-contributor-arbitrary-svg-download","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary SVG file download in all versions up to, and including, 3.22.1. This is due to the plugin not properly restricting access to files. This makes it possible for authenticated attackers, with contributor-level access and above, to download arbitrary SVG files.","date":"2024-06-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"h","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"8fd62dd4947e336959bfb51eb7a3ae3aaa309cd7efb7e9824148d02272c4345e","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.24.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.24.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5416","name":"CVE-2024-5416","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5416","description":"[en] The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in Elementor Editor pages. This was partially patched in version 3.23.2.","date":"2024-09-11"},{"id":"f49baad5636f848f4e60e082727ce96beb4e4d2c","name":"Elementor Website Builder \u2013 More than Just a Page Builder <= 3.23.4 – Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-more-than-just-a-page-builder-3234-authenticated-contributor-stored-cross-site-scripting-in-the-url-parameter-in-multiple-widgets","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in Elementor Editor pages. This was partially patched in version 3.23.2.","date":"2024-09-10"},{"id":"f9ec73606c0463cacb8e9475ecb967c82bd0b6b0","name":"WordPress Elementor Website Builder Plugin <= 3.23.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-plugin-3-23-4-authenticated-contributor-stored-cross-site-scripting-in-the-url-parameter-in-multiple-widgets-vulnerability","description":"

WordPress Elementor Website Builder Plugin <= 3.23.4 is vulnerable to Cross Site Scripting (XSS)

Software: Elementor Website Builder

Link: https:\/\/wordpress.org\/plugins\/elementor\/#developers

Affected Version <= 3.23.4

Fixed in version 3.24.0 “,”date”:”2024-09-11″}],”impact”:{“cvss”:{“version”:”3.1″,”vector”:”CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N”,”av”:”n”,”ac”:”l”,”pr”:”l”,”ui”:”r”,”s”:”c”,”c”:”l”,”i”:”l”,”a”:”n”,”score”:”5.4″,”severity”:”m”,”exploitable”:”0.0″,”impact”:”0.0″},”cwe”:[{“cwe”:”CWE-79″,”name”:”Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)”,”description”:”The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.”}]}},{“uuid”:”6e08b143ee6ce544b0bcf144616d2f04e3dff2128b34c417a0398c08d151e151″,”name”:”Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.24.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.24.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6757","name":"CVE-2024-6757","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6757","description":"[en] The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.","date":"2024-10-15"},{"id":"dbef1f34e17ef97d7402ea564f760021e7fcdeb6","name":"WordPress Elementor Website Builder Plugin <= 3.24.5 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-24-5-authenticated-contributor-basic-information-exposure-via-get-image-alt-function-vulnerability","description":"

WordPress Elementor Website Builder Plugin <= 3.24.5 is vulnerable to Sensitive Data Exposure

Software: Elementor Website Builder

Link: https:\/\/wordpress.org\/plugins\/elementor\/#developers

Affected Version <= 3.24.5

Fixed in version 3.24.6 “,”date”:”2024-10-14″},{“id”:”2f829d420d7d1d84b516c1c4e27597090a513752″,”name”:”Elementor <= 3.23.5 – Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3235-authenticated-contributor-basic-information-exposure-via-get-image-alt-function","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.","date":"2024-10-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"c10385e351179443564f92d5c392907b63167b1278aace50dd030de243f47195","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.25.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.25.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8236","name":"CVE-2024-8236","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8236","description":"[en] The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018url\u2019 parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-11-26"},{"id":"26ed1e224cd813c2f6f83bff42e81f2cb390d5f7","name":"Elementor Website Builder \u2013 More than Just a Page Builder <= 3.25.7 – Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-more-than-just-a-page-builder-3257-authenticated-contributor-stored-cross-site-scripting","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018url\u2019 parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-11-25"},{"id":"1614443cfaf194260d8447a5ce9124b8ae4a987f","name":"WordPress Elementor Website Builder Plugin <= 3.25.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-website-builder-more-than-just-a-page-builder-plugin-3-25-7-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"

WordPress Elementor Website Builder Plugin <= 3.25.7 is vulnerable to Cross Site Scripting (XSS)

Software: Elementor Website Builder

Link: https:\/\/wordpress.org\/plugins\/elementor\/#developers

Affected Version <= 3.25.7

Fixed in version 3.25.8 “,”date”:”2024-11-26″}],”impact”:{“cvss”:{“version”:”3.1″,”vector”:”CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N”,”av”:”n”,”ac”:”l”,”pr”:”l”,”ui”:”n”,”s”:”c”,”c”:”l”,”i”:”l”,”a”:”n”,”score”:”6.4″,”severity”:”m”,”exploitable”:”0.0″,”impact”:”0.0″},”cwe”:[{“cwe”:”CWE-79″,”name”:”Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)”,”description”:”The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.”}]}},{“uuid”:”daba0c5a76da359ad7086e48d80f357e3b1803d69fd2b6ea3c3445b736bea048″,”name”:”Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.25.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.25.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10453","name":"CVE-2024-10453","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10453","description":"[en] The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-21"},{"id":"f7c148d1778946f49d673da8e570317ebb829077","name":"Elementor Website Builder \u2013 More than Just a Page Builder <= 3.25.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-more-than-just-a-page-builder-3259-authenticated-contributor-stored-cross-site-scripting-via-typography-settings","description":"The Elementor Website Builder \u2013 More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-20"},{"id":"1c7b9ea156ea85560e5f9619c8e3733f63ad050e","name":"WordPress Elementor Website Builder Plugin <= 3.25.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-25-9-authenticated-contributor-stored-cross-site-scripting-via-typography-settings-vulnerability","description":"

WordPress Elementor Website Builder Plugin <= 3.25.9 is vulnerable to Cross Site Scripting (XSS)

Software: Elementor Website Builder

Fixed in version 3.25.10

Affected Version <= 3.25.9

CVE: CVE-2024-10453″,”date”:”2024-12-23″}],”impact”:{“cvss”:{“version”:”3.1″,”vector”:”CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N”,”av”:”n”,”ac”:”l”,”pr”:”l”,”ui”:”n”,”s”:”c”,”c”:”l”,”i”:”l”,”a”:”n”,”score”:”6.4″,”severity”:”m”,”exploitable”:”0.0″,”impact”:”0.0″},”cwe”:[{“cwe”:”CWE-79″,”name”:”Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)”,”description”:”The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.”}]}},{“uuid”:”74e66a87e11a974d06323ca98b14366a8f96219966ac9415cc6d1f6177ae72b4″,”name”:”Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.27.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.27.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-13445","name":"CVE-2024-13445","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-13445","description":"[en] The Elementor Website Builder \u2013 More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-02-20"},{"id":"4d06bf134a4e753f2f01a0c793f15480f4290692","name":"Elementor Website Builder – More Than Just a Page Builder <= 3.27.4 – Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-more-than-just-a-page-builder-3274-authenticated-contributor-stored-cross-site-scripting","description":"The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null},{"id":"EUVD-2025-4628","name":"EUVD-2025-4628","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-4628","description":"The Elementor Website Builder \u2013 More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-02-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"6e592a4218a8283ebde680b4198a432f21da1b851e216099f336e4032c65e7f4","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.25.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.25.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-54444","name":"CVE-2024-54444","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-54444","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder allows Stored XSS. This issue affects Elementor Website Builder: from n\/a through 3.25.10.","date":"2025-02-25"},{"id":"146ea055d26599e91b257e360a5b74a91e938878","name":"Elementor Website Builder <= 3.25.10 – Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-website-builder-32510-authenticated-contributor-stored-cross-site-scripting","description":"The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.25.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null},{"id":"EUVD-2024-53932","name":"EUVD-2024-53932","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-53932","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder allows Stored XSS. This issue affects Elementor Website Builder: from n\/a through 3.25.10.","date":"2025-02-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"ea3419438943b8675464ddc661614a168fc4287659172bd0baccced184111b4c","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.29.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.29.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50555","name":"CVE-2024-50555","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50555","description":"","date":null},{"id":"762b610b4f00923a6be4ecac3a070e5468f3a63b","name":"Elementor Website Builder <= 3.29.0 – Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/elementor-website-builder-3290-authenticated-contributor-stored-cross-site-scripting","description":"The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":[]},{"uuid":"13da65bbf7d4add607caf70e63be2c6f8c94d8daeaedd0d9bd68df507d56522f","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.30.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.30.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4566","name":"CVE-2025-4566","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4566","description":"","date":null},{"id":"9e86676dd0f0a09556ee594444e625ebca6c2cd9","name":"Elementor <= 3.30.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3302-authenticated-contributor-stored-cross-site-scripting-via-text-path-widget","description":"The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This attack affects only Chrome\/Edge browsers","date":null}],"impact":[]},{"uuid":"1791d0357c7dab2d9d1a6ffccb6c49bcfc9605e4eecaacc54ac7d917acd90725","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.29.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.29.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3075","name":"CVE-2025-3075","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3075","description":"","date":null},{"id":"b9f31b84e9a2f4e2bb7721c649b9e9b5b5d2777d","name":"Elementor <= 3.29.0 – Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3290-authenticated-contributor-stored-cross-site-scripting","description":"The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts sites with 'Element Caching' enabled.","date":null}],"impact":[]},{"uuid":"de0e1caa12378bc1cca0a0dcf61496e87a9a1da04defe9d502a45836b041b214","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] < 3.30.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.30.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-8081","name":"CVE-2025-8081","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-8081","description":"","date":null},{"id":"88f61d14cfeabfd97be39d8e434f13be8f500ab1","name":"Elementor <= 3.30.2 – Authenticated (Administrator+) Arbitrary File Read via Image Import","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementor\/elementor-3302-authenticated-administrator-arbitrary-file-read-via-image-import","description":"The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.","date":null}],"impact":[]},{"uuid":"e1101994bd81b019dfc2baeb73bbf442a487c2dc0900d8db083d65aa772bab44","name":"Elementor Website Builder – More Than Just a Page Builder [elementor] <= 3.33.0 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.33.0","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2025-67588","name":"CVE-2025-67588","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-67588","description":"[en] Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n\/a through <= 3.33.0.","date":"2025-12-09"}],"impact":[]}]},"updated":"1765363486"}