WordPress Plugin Vulnerabilities

Premium Addons for Elementor < 4.10.19 - Contributor+ Stored Cross-Site Scripting

Description

The plugin does not prevent users with at least the contributor role from conducting Stored XSS attacks via the plugin's onClick Event functionality.

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Webbernaut
Verified
No

Timeline

Publicly Published
2024-02-14 (about 2 years ago)
Added
2024-02-15 (about 2 years ago)
Last Updated
2024-02-15 (about 2 years ago)

Other