CVE · Medium

CVE-2024-35656 — Elementor Pro [elementor-pro] < 3.21.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-35656 Elementor Pro [elementor-pro] < 3.21.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.21.3 3.21.3 2024-06-28

CVE-2024-35656

Elementor Pro versions through 3.21.2 contain a reflected cross-site scripting vulnerability caused by inadequate sanitization of user input and lack of proper output encoding. An unauthenticated attacker could exploit this flaw by crafting a malicious link that, when clicked by a user, would execute arbitrary JavaScript code in the victim's browser. The issue was addressed in version 3.21.3 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.