PT-2021-23592 · Elementor+1 · Elementor+1

Ramuel Gall

·

Published

2021-11-17

·

Updated

2021-11-19

·

CVE-2021-42360

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions WordPress (affected versions not specified)
Description The issue allows users with the edit posts capability to import blocks onto any page using the "astra-page-elementor-batch-process" AJAX action. An attacker can craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to "astra-page-elementor-batch-process" and the url parameter pointed to their remotely-hosted malicious block, as well as an id parameter containing the post or page to overwrite. Any post or page that had been built with Elementor, including published pages, could be overwritten by the imported block, and the malicious JavaScript in the imported block would then be executed in the browser of any visitors to that page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42360

Affected Products

Elementor
Wordpress