CVE · Medium

CVE-2021-24259 — Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24259 Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.11.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.11.2 1.11.2 2021-04-13

CVE-2021-24259

Addon Elements for Elementor prior to version 1.11.2 contains stored cross-site scripting vulnerabilities in multiple widgets that can be exploited by users with contributor-level permissions. The Flip Box widget's "front_title_html_tag" and "back_title_html_tag" parameters accept arbitrary JavaScript code instead of restricting input to legitimate HTML tags, as does the Price Table widget through its "heading_tag" and "sub_heading_tag" parameters. The Split Text, Text Separator, and Timeline widgets are similarly vulnerable through their respective tag and parameter fields. When affected pages are viewed or previewed, the injected malicious scripts execute in the browser.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.