PT-2021-23592 · Elementor+1 · Elementor+1
Ramuel Gall
·
Published
2021-11-17
·
Updated
2021-11-19
·
CVE-2021-42360
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
WordPress (affected versions not specified)
Description
The issue allows users with the
edit posts capability to import blocks onto any page using the "astra-page-elementor-batch-process" AJAX action. An attacker can craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to "astra-page-elementor-batch-process" and the url parameter pointed to their remotely-hosted malicious block, as well as an id parameter containing the post or page to overwrite. Any post or page that had been built with Elementor, including published pages, could be overwritten by the imported block, and the malicious JavaScript in the imported block would then be executed in the browser of any visitors to that page.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elementor
Wordpress