WordPress Community Forum

WordPress Support => WordPress Vulnerability => Topic started by: Kailash on Jun 13, 2022, 08:08 AM

Title: WordPress Elementor plugin <= 3.5.5 - Cross-Site Scripting (XSS) Vulnerability
Post by: Kailash on Jun 13, 2022, 08:08 AM
WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability

Plugin name: Elementor Website Builder
Vulnerable versions: <= 3.5.5
Fixed in: 3.5.6
CVE ID: CVE-2022-29455
Classification: Cross Site Scripting (XSS)
Publicly disclosed: 2022-06-13

Vulnerability Details

Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability discovered by Rotem Bar (Patchstack Alliance) in WordPress Elementor plugin (versions <= 3.5.5).

Solution

Update the WordPress Elementor plugin to the latest available version (at least 3.5.6).

Plugin Link: https://wordpress.org/plugins/elementor/