PowerPack Addons for Elementor < 2.6.2 - Reflected Cross-Site Scripting
CVE-2021-25027
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 3 January 2022
What is CVE-2021-25027?
The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
Affected Version(s)
PowerPack Addons for Elementor 2.6.2