Vulnerabilities > Elementor > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-03-27 | CVE-2024-2120 | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Navigation widget in all versions up to, and including, 3.20.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-02-29 | CVE-2024-0506 | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. | 5.4 |
2023-11-30 | CVE-2023-47505 | Unspecified vulnerability in Elementor Website Builder Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4. | 5.4 |
2023-08-14 | CVE-2022-4953 | Unspecified vulnerability in Elementor Website Builder The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. | 6.1 |
2023-06-07 | CVE-2020-36703 | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts. | 5.4 |
2022-06-13 | CVE-2022-29455 | Unspecified vulnerability in Elementor Website Builder DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions. | 6.1 |
2021-11-23 | CVE-2021-24891 | Unspecified vulnerability in Elementor Website Builder The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue. | 6.1 |
2021-04-05 | CVE-2021-24206 | Cross-site Scripting vulnerability in Elementor Website Builder In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. | 5.4 |
2021-04-05 | CVE-2021-24205 | Cross-site Scripting vulnerability in Elementor Website Builder In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. | 5.4 |
2021-04-05 | CVE-2021-24204 | Cross-site Scripting vulnerability in Elementor Website Builder In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. | 5.4 |