NA

CVE-2022-4953

Published: 14/08/2023 Updated: 16/01/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Elementor Website Builder WordPress plugin prior to 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.

Vulnerable Product Search on Vulmon Subscribe to Product

elementor website builder

Exploits

WordPress Elementor plugin versions prior to 355 suffer from an iframe injection vulnerability ...