The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.jbelamor.com/xss-elementor-lightox.html | third party advisory exploit |
https://wpscan.com/vulnerability/fbed0daa-007d-4f91-8d87-4bca7781de2d | third party advisory exploit |