CVE-2021-24269
The Sina Extension for Elementor plugin before version 3.3.12 contains multiple stored cross-site scripting vulnerabilities that can be exploited by users with contributor-level access or higher. Several widgets including Banner Slider, Sina Content Slider, Sina Particle Layer, and Sina Title accept parameters such as title_tag and subtitle_tag that fail to properly sanitize or escape user input, allowing arbitrary JavaScript to be injected and executed when pages are viewed or previewed. The vulnerability exists because while the interface presents a fixed list of acceptable HTML tags, the underlying save_builder request does not filter malicious scripts from these parameters. Users running versions before 3.3.12 should update immediately to remediate this risk.
Based on public CVE data (MITRE/NVD).