Cross-Site Scripting vulnerabilities were found on the popular WordPress website builder plugin Elementor, installed on over 7 million websites. The vulnerability allows users with access to the Elementor editor to add Javascript to posts which can result to site take-over in the worst cases.
Initial patches were implemented starting from version 3.1.2, however, further fixes have been applied since then, so we recommend updating to the latest version available.
For more information, please check the official public release.
If you have questions, don’t hesitate to contact our support team.
Leave a Reply