Lucene search

K
wpvulndbWpvulndbWPVDB-ID:096FFE18-7540-4763-A734-B0C40DFC4922
HistoryFeb 15, 2024 - 12:00 a.m.

PowerPack Addons for Elementor < 2.7.16 - Contributor+ Stored Cross-Site Scripting

2024-02-1500:00:00
wpscan.com
5
elementor
powerpack addons
cross-site scripting
contributor
twitter buttons widget

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The plugin does not properly sanitize its Twitter Buttons Widget setting, allowing users with at least the contributor role to conduct Stored XSS attacks.

CPENameOperatorVersion
eq2.7.16

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:096FFE18-7540-4763-A734-B0C40DFC4922