Stored Cross-Site Scripting in Elementor Addon Elements Plugin for WordPress
CVE-2023-5381

4.4MEDIUM

What is CVE-2023-5381?

The Elementor Addon Elements plugin for WordPress contains a vulnerability that allows authenticated attackers with administrator-level permissions to execute arbitrary web scripts via stored cross-site scripting attacks. This issue arises from inadequate input sanitization and output escaping in admin settings within affected versions, specifically those up to and including 1.12.7. The vulnerability is particularly concerning for multi-site installations and those where unfiltered_html is disabled, as it enables the possibility of malicious scripts being run when users access compromised pages.

Affected Version(s)

Addon Elements for Elementor (formerly Elementor Addon Elements) 0 <= 1.12.7

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Paolo Tresso
.