Medium severity6.1NVD Advisory· Published Nov 23, 2021· Updated Jun 17, 2026
CVE-2021-24891
CVE-2021-24891
Description
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:elementor:website_builder:*:*:*:*:*:wordpress:*:*Range: >1.5.0,<3.1.4
- WordPress/Elementor Website Builder plugindescription
- Range: <3.4.8
Patches
Vulnerability mechanics
References
2- wpscan.com/vulnerability/fbed0daa-007d-4f91-8d87-4bca7781de2dnvdExploitThird Party Advisory
- www.jbelamor.com/xss-elementor-lightox.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.