The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-06-05T21:23:37
Updated: 2024-08-04T12:32:13.999Z
Reserved: 2020-06-04T00:00:00
Link: CVE-2020-13865
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-06-05T22:15:12.150
Modified: 2024-11-21T05:02:02.140
Link: CVE-2020-13865
Redhat
No data.