Input validation vulnerability in Premium Addons for Elementor 4.10.16

The Premium Addons for Elementor plugin, which is used on WordPress websites, has a security issue. This vulnerability is called Stored Cross-Site Scripting and it affects all versions of the plugin up to 4.10.16. This is because the plugin does not properly clean up or protect against harmful web scripts that are added into URLs by users. This means that attackers who have access to the website as a contributor or higher can insert their own scripts into pages, which will run whenever someone visits those pages.

Detected in:

Premium Addons for Elementor fixed vulnerable versions: >= * <= 4.10.16

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.