Input validation vulnerability in Stratum – Elementor Widgets 1.4.7

The Stratum – Elementor Widgets plugin used in WordPress has a security issue where hackers can inject harmful code into a website using the plugin’s Image Hotspot widget. This can happen in all versions of the plugin up to version 1.4.7. The problem is caused by not properly checking and cleaning any user-provided information. Attackers who have contributor-level access or higher can take advantage of this vulnerability and add malicious scripts to pages that will run whenever someone visits those pages.

Detected in:

Stratum – Elementor Widgets fixed vulnerable versions: >= * <= 1.4.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.