CVE-2021-24255
The Essential Addons for Elementor Lite plugin before version 4.5.4 contains multiple stored cross-site scripting vulnerabilities affecting several widgets that can be exploited by users with contributor-level permissions or higher. The Progress Bar and Woo Product Compare widgets fail to properly sanitize and escape parameters intended for HTML tag selection, allowing attackers to inject malicious JavaScript code through builder save requests. Additional vulnerable widgets include Advanced Accordion, Creative Button, Dual Color Header, Fancy Text, Filterable Gallery, and Flipbox, each with specific parameters that do not filter or escape user input before rendering. When affected pages are viewed or previewed, the injected scripts execute in the browser of anyone accessing the content.
Based on public CVE data (MITRE/NVD).