CVE-2020-13865
05.06.2020, 22:15
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
Vendor | Product | Version |
---|---|---|
elementor | elementor_page_builder | 𝑥 < 2.9.9 |
𝑥
= Vulnerable software versions