A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/elementor/#developers | Product Third Party Advisory |
Configurations
Information
Published : 2020-09-16 13:15
Updated : 2020-09-18 13:30
NVD link : CVE-2020-20406
Mitre link : CVE-2020-20406
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
elementor
- elementor_page_builder