Lucene search

K
wpvulndbJeremy BuisWPVDB-ID:31659B56-2046-4BE8-887F-A016DA138595
HistoryJun 05, 2020 - 12:00 a.m.

Elementor Page Builder < 2.9.10 - Authenticated Stored XSS

2020-06-0500:00:00
Jeremy Buis
wpscan.com
7

EPSS

0.001

Percentile

24.8%

The Elementor Page Builder plugin is susceptible to stored XSS. An author user can create custom links containing XSS payloads or apply custom attributes to widgets which results in XSS.

PoC

javascript:alert(1), JaVaScript:alert(1), javas cript:alert(1)

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:31659B56-2046-4BE8-887F-A016DA138595