Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2022-29455 — Cross-site Scripting in Website Builder
Severity
6.1MEDIUMNVD
CNA4.7
EPSS
49.4%
top 2.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 13
Latest updateJun 14
Description
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
2💥Exploits & PoCs
2Nuclei▶
WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting
Nuclei▶
WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting