WordPress Community Forum
WordPress Support => WordPress Vulnerability => Topic started by: Kailash on Jun 13, 2022, 08:08 AM
WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability
Plugin name: Elementor Website Builder
Vulnerable versions: <= 3.5.5
Fixed in: 3.5.6
CVE ID: CVE-2022-29455
Classification: Cross Site Scripting (XSS)
Publicly disclosed: 2022-06-13
Vulnerability Details
Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability discovered by Rotem Bar (Patchstack Alliance) in WordPress Elementor plugin (versions <= 3.5.5).
Solution
Update the WordPress Elementor plugin to the latest available version (at least 3.5.6).
Plugin Link: https://wordpress.org/plugins/elementor/