logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2020-36703

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2020-36703

Description:
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
Last updated date:
06/12/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/12/2023
Reference url to background

https://blog.nintechnet.com/wordpress-elementor-plugin-fixed-svg-xss-protection-bypass-vulnerability/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy