Back

MEDIUM

Essential Addons for Elementor Lite <= 5.0.8 Reflected Cross-Site Scripting

Published Feb 24, 2022

Description

The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~/includes/Traits/Helper.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 5.0.8.

Affected products

Remediation

Vendor solution

Update to version 5.0.9 or newer.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Feb 24, 2022
Updated Jan 31, 2025
Reserved Feb 18, 2022
CISA Vulnrichment
Updated Jan 31, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Wordfence
Published Feb 24, 2022
Updated Jan 31, 2025
Exploited since n/a
EUVD-2022-15768