CVE · High

CVE-2023-33999 — Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-33999 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 5.2.1 5.2.1 2023-07-18

CVE-2023-33999

A cross-site scripting vulnerability in Element Pack Addons for Elementor versions before 5.2.1 could permit an attacker to inject malicious scripts into a website, which would then execute for visitors. The flaw affects the plugin's various features including headers, footers, grids, carousels, tables, animations, forms, and Twitter integration. Attackers could exploit this to deliver redirects, advertisements, or arbitrary HTML content to site users. The vulnerability was patched in version 5.2.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.