PT-2026-64844 · WordPress · Sina Extension For Elementor
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sina Extension for Elementor versions prior to 3.10.2
Description
An unauthenticated AJAX handler fails to escape a value reconstructed from request input before reflecting it into the HTML response. This allows unauthenticated attackers to execute arbitrary JavaScript in the browser of users who trigger a crafted request, leading to a Reflected Cross-Site Scripting (XSS) attack. Cross-Site Scripting is a technique where malicious scripts are injected into trusted websites.
Recommendations
Update Sina Extension for Elementor to version 3.10.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sina Extension For Elementor