CVE · Medium

CVE-2020-8426 — Elementor Website Builder – more than just a page builder [elementor] < 2.8.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-8426 Elementor Website Builder – more than just a page builder [elementor] < 2.8.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.8.5 2.8.5 2020-01-28

CVE-2020-8426

The Elementor Website Builder plugin prior to version 2.8.5 contains a reflected cross-site scripting vulnerability accessible through the elementor-system-info page. An attacker could exploit this flaw by crafting a malicious link and tricking an authenticated WordPress user into clicking it, potentially allowing execution of arbitrary JavaScript in the victim's browser session.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.