Input validation vulnerability in Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) 5.5.3

The Element Pack add-on for Elementor on WordPress has a security issue where malicious code can be injected through a link. This can be done by attackers who have contributor-level access or higher, and the code will run whenever someone visits the page with the injected link. This vulnerability has been identified in versions up to and including 5.5.3, and is caused by a lack of proper input sanitization and output escaping. It is similar to a previous security concern known as CVE-2024-1429.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.