Total vulnerabilities in the database
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
Software | From | Fixed in |
---|---|---|
elementor / website_builder | 1.5.0.x | 3.1.4 |
elementor / website_builder | 3.2.0 | 3.4.8 |
![]() |
- | 3.4.8 |