CVE · Medium

CVE-2022-4953 — Elementor Website Builder – more than just a page builder [elementor] < 3.5.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4953 Elementor Website Builder – more than just a page builder [elementor] < 3.5.5 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 6.1 < 3.5.5 3.5.5 2023-07-19

CVE-2022-4953

The Elementor page builder plugin is susceptible to reflected cross-site scripting attacks through the 'settings' hash parameter in version 3.5.4 and earlier because user input is not properly sanitized or escaped. An unauthenticated attacker could craft a malicious link that, when clicked by a user, injects arbitrary iframes into pages that would then execute in the victim's browser. This vulnerability was fixed in version 3.5.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.