Headline
CVE-2022-29455: WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability - Patchstack
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor’s Elementor Website Builder plugin <= 3.5.5 versions.
Verified
Fixed
4.7
CVSS 3.1 score Medium severity
Monitoring Coming soon
PSID
3aba37f2a40a
Classification
Cross Site Scripting (XSS)
OWASP Top 10
A7: Cross-Site Scripting (XSS)
Publicly disclosed
2022-06-13
Details
Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability discovered by Rotem Bar (Patchstack Alliance) in WordPress Elementor plugin (versions <= 3.5.5).
Solution
Update the WordPress Elementor plugin to the latest available version (at least 3.5.6).
References
Vulnerability details