PT-2022-13356 · Unknown · Essential Addons For Elementor

Published

2022-02-24

·

Updated

2022-03-03

·

CVE-2022-0683

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Essential Addons for Elementor Lite versions up to and including 5.0.8
Description The issue arises from insufficient escaping and sanitization of the settings parameter in the ~/includes/Traits/Helper.php file, allowing attackers to inject arbitrary web scripts onto a page. This script executes when a user clicks on a specially crafted link created by an attacker.
Recommendations For versions up to and including 5.0.8, update to a version that includes the necessary escaping and sanitization fixes for the settings parameter to prevent Cross-Site Scripting attacks.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0683

Affected Products

Essential Addons For Elementor