CVE · Medium

CVE-2021-24891 — Elementor Website Builder – more than just a page builder [elementor] < 3.6.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24891 Elementor Website Builder – more than just a page builder [elementor] < 3.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.6.3 3.6.3 2021-03-23

CVE-2021-24891

The Elementor Website Builder plugin contains a DOM-based cross-site scripting flaw in versions through 3.4.7 that stems from inadequate sanitization of the '#elementor-action:action=lightbox&settings=' parameter and lack of proper output escaping. Unauthenticated attackers could exploit this vulnerability by injecting malicious scripts that execute when a user is deceived into clicking a crafted link. The issue was fixed in version 3.6.3 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.