Input validation vulnerability in Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders 5.9.19

The Essential Addons for Elementor plugin for WordPress has a vulnerability that allows attackers to inject harmful web scripts into pages using the ‘Dual Color Header’, ‘Event Calendar’, and ‘Advanced Data Table’ widgets. This can happen on any version up to 5.9.19, and even if the attacker only has contributor-level access. This means that when a user visits the affected page, the harmful script will be executed.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.