Name of the Vulnerable Software and Affected Versions:
Sky Addons for Elementor plugin versions up to and including 3.1.4
Description:
The Sky Addons for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through multiple widgets. Insufficient input sanitization and output escaping on user-supplied attributes allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page.
Recommendations:
Update Sky Addons for Elementor plugin to a version later than 3.1.4.