Cross-site Scripting Vulnerability in Elementor Website Builder
CVE-2024-50555
6.5MEDIUM
What is CVE-2024-50555?
A cross-site scripting vulnerability has been identified in the Elementor Website Builder. This flaw arises from improper neutralization of user-supplied input during web page generation. As a result, this vulnerability can facilitate stored XSS attacks, with attackers potentially injecting malicious scripts into web pages viewed by other users. The affected versions of Elementor are those prior to 3.29.0, leaving sites using these versions vulnerable to exploitation.
Affected Version(s)
Elementor Website Builder 0 <= 3.29.0