CVE-2024-1521
Elementor Pro through version 3.20.1 contains a stored cross-site scripting vulnerability affecting its Form widget, which permits authenticated users with contributor privileges or higher to upload malicious SVGZ files due to inadequate sanitization and escaping of user inputs. The injected scripts execute when visitors access pages containing the compromised content. This vulnerability only affects websites running on NGINX servers and does not impact those using Apache HTTP Server. The flaw was patched in version 3.20.2.
Based on public CVE data (MITRE/NVD).