CVE · Medium

CVE-2021-24269 — Sina Extension for Elementor [sina-extension-for-elementor] < 3.3.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24269 Sina Extension for Elementor [sina-extension-for-elementor] < 3.3.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.3.12 3.3.12 2021-04-13

CVE-2021-24269

The Sina Extension for Elementor plugin before version 3.3.12 contains multiple stored cross-site scripting vulnerabilities that can be exploited by users with contributor-level access or higher. Several widgets including Banner Slider, Sina Content Slider, Sina Particle Layer, and Sina Title accept parameters such as title_tag and subtitle_tag that fail to properly sanitize or escape user input, allowing arbitrary JavaScript to be injected and executed when pages are viewed or previewed. The vulnerability exists because while the interface presents a fixed list of acceptable HTML tags, the underlying save_builder request does not filter malicious scripts from these parameters. Users running versions before 3.3.12 should update immediately to remediate this risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.