Unrated severityNVD Advisory· Published Nov 23, 2021· Updated Aug 3, 2024
Elementor < 3.4.8 - DOM Cross-Site-Scripting
CVE-2021-24891
Description
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/Elementor Website Builder plugindescription
Patches
Vulnerability mechanics
References
2- wpscan.com/vulnerability/fbed0daa-007d-4f91-8d87-4bca7781de2dmitrex_refsource_MISC
- www.jbelamor.com/xss-elementor-lightox.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.