Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2021-24891

Severity
6.1MEDIUM
EPSS
5.3%
top 9.93%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 23
Latest updateMay 24

Description

The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDelementor/website_builder3.2.03.4.8+1
CVEListV5unknown/elementor_website_builder3.4.83.4.8

🔴Vulnerability Details

2
GHSA
GHSA-26jf-gmgg-9m8f: The Elementor Website Builder WordPress plugin before 32022-05-24
CVEList
Elementor < 3.4.8 - DOM Cross-Site-Scripting2021-11-23

💥Exploits & PoCs

1
Nuclei
WordPress Elementor Website Builder <3.1.4 - Cross-Site Scripting
CVE-2021-24891 (MEDIUM CVSS 6.1) | The Elementor Website Builder WordP | cvebase.io