Input validation vulnerability in ElementInvader Addons for Elementor 1.2.7

The ElementInvader Addons for Elementor plugin, which is used on WordPress websites, has a security issue. This issue, known as Stored Cross-Site Scripting, affects versions 1.2.7 and below. This happens because the plugin does not properly clean up text that is entered, allowing attackers with certain access levels to add harmful code to web pages. This code can then run whenever a user visits the affected page.

Detected in:

ElementInvader Addons for Elementor fixed vulnerable versions: >= * <= 1.2.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.