CVE · Medium

CVE-2021-24257 — Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.2.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24257 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.2.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.2.8 4.2.8 2021-04-13

CVE-2021-24257

The Premium Addons for Elementor plugin before version 4.2.8 contains stored cross-site scripting vulnerabilities in multiple widgets that can be exploited by lower-privileged users such as contributors. Attackers can inject malicious JavaScript through various widget parameters including the Testimonials widget's name and company name size fields, the Premium Blog widget's title tag, and parameters in the Banner, Dual Header, Person, Pricing Table, and Title widgets by bypassing incomplete input sanitization. The injected scripts execute when pages containing these widgets are viewed or previewed. These vulnerabilities stem from inadequate filtering of externally sourced JavaScript in widget configuration parameters.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.