PT-2022-13356 · Unknown · Essential Addons For Elementor
Published
2022-02-24
·
Updated
2022-03-03
·
CVE-2022-0683
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Essential Addons for Elementor Lite versions up to and including 5.0.8
Description
The issue arises from insufficient escaping and sanitization of the
settings parameter in the ~/includes/Traits/Helper.php file, allowing attackers to inject arbitrary web scripts onto a page. This script executes when a user clicks on a specially crafted link created by an attacker.Recommendations
For versions up to and including 5.0.8, update to a version that includes the necessary escaping and sanitization fixes for the
settings parameter to prevent Cross-Site Scripting attacks.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Essential Addons For Elementor