The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
| Software | From | Fixed in |
|---|---|---|
| elementor / elementor_page_builder | - | 2.9.9 |