Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2022-29455Cross-site Scripting in Website Builder

Severity
6.1MEDIUMNVD
CNA4.7
EPSS
49.4%
top 2.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 13
Latest updateJun 14

Description

DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-9gjm-mrgw-7qq8: DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 32022-06-14
CVEList
WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability2022-06-13

💥Exploits & PoCs

2
Nuclei
WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting
Nuclei
WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting
CVE-2022-29455 — Cross-site Scripting | cvebase