CVE · Medium

CVE-2021-24256 — Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.5.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24256 Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.5.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.8 1.5.8 2021-04-13

CVE-2021-24256

The Elementor – Header, Footer & Blocks Template plugin before version 1.5.8 contains stored XSS vulnerabilities in two widgets that can be exploited by contributors and other lower-privileged users. Both the Page Title and Site Title widgets fail to properly validate the "heading_tag" parameter, allowing attackers to inject script tags or reference remote JavaScript files through parameter manipulation. When a page containing these malicious widgets is viewed or previewed, the injected or remotely hosted JavaScript executes in visitors' browsers, compromising site security.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.