CVE-2021-24258
ElementsKit Elementor Addons through version 2.1.x contains multiple stored cross-site scripting vulnerabilities affecting several widgets, including fun fact, heading, icon box, image box, pricing, and motion text (pro only). Users with lower privileges such as contributors can inject malicious JavaScript through various parameters like ekit_funfact_title_size, ekit_heading_title_tag, ekit_icon_box_title_size, ekit_image_box_title_size, ekit_pricing_title_size, and ekit_motion_text_sub_title_tag by sending modified save_builder requests. The injected code executes when administrators, editors, or other users view or preview the compromised posts. The vulnerability was fixed in version 2.2.0.
Based on public CVE data (MITRE/NVD).