Vulnerabilities > CVE-2021-24351 - Unspecified vulnerability in Posimyth the Plus Addons for Elementor

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
posimyth

Summary

The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)

Vulnerable Configurations

Part Description Count
Application
Posimyth
63