CVE-2021-42360
The Starter Templates plugin for WordPress versions below 2.7.1 contained a vulnerability in sites running Elementor that allowed users with edit_posts capability, including Contributors, to import arbitrary blocks onto pages through the astra-page-elementor-batch-process AJAX action. An attacker could host malicious JavaScript in a block on a remote server and use an AJAX request to inject this block into any Elementor-built post or page, executing the malicious code in visitors' browsers. This vulnerability affected any published or unpublished content created with Elementor and could result in unauthorized page modification and client-side code execution.
Based on public CVE data (MITRE/NVD).