
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2021-24202) affects the Elementor Website Builder WordPress plugin versions before 3.1.4. This authenticated stored Cross-Site Scripting (XSS) vulnerability was discovered in the heading widget component. The issue was publicly disclosed on March 17, 2021, and was discovered by security researcher Ramuel Gall (WPScan).
The vulnerability exists in the heading widget (includes/widgets/heading.php) which accepts a 'header_size' parameter. Although the element control lists a fixed set of possible HTML tags, users with Contributor or higher permissions can send a modified 'save_builder' request with this parameter set to 'script' combined with a 'title' parameter containing JavaScript. The injected JavaScript code will then be executed when the saved page is viewed or previewed. The vulnerability has been assigned a CVSS score of 6.4 (medium) and is classified as CWE-79 (WPScan).
This vulnerability allows authenticated users with Contributor or higher permissions to inject and store malicious JavaScript code that executes when other users view or preview the affected pages. This could lead to potential client-side attacks against site visitors and administrators (WPScan).
The vulnerability requires an authenticated user with at least Contributor-level permissions to exploit. A proof of concept exploit has been publicly documented, demonstrating how an attacker can inject JavaScript code through the heading widget's parameters (WPScan).
The vulnerability has been fixed in Elementor Website Builder version 3.1.4. Site administrators are strongly advised to update to this version or later to mitigate the risk (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."