CVE · Medium

CVE-2024-1521 — Elementor Pro [elementor-pro] < 3.20.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1521 Elementor Pro [elementor-pro] < 3.20.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.20.2 3.20.2 2024-03-26

CVE-2024-1521

Elementor Pro through version 3.20.1 contains a stored cross-site scripting vulnerability affecting its Form widget, which permits authenticated users with contributor privileges or higher to upload malicious SVGZ files due to inadequate sanitization and escaping of user inputs. The injected scripts execute when visitors access pages containing the compromised content. This vulnerability only affects websites running on NGINX servers and does not impact those using Apache HTTP Server. The flaw was patched in version 3.20.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.