VYPR
Unrated severityNVD Advisory· Published May 5, 2021· Updated Aug 3, 2024

DethemeKit For Elementor < 1.5.5.5 - Contributor+ Stored XSS

CVE-2021-24270

Description

The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.