Input validation vulnerability in The Plus Addons for Elementor Page Builder 5.5.4

A popular plugin for WordPress called The Plus Addons for Elementor Page Builder has a security issue. This issue, known as Stored Cross-Site Scripting, allows hackers to insert harmful code into certain parts of the plugin. This can happen when the ‘size’ setting is used in the Heading Title widget. The problem affects all versions of the plugin up to version 5.5.4 and can be exploited by people with contributor-level access or higher. This means that if you use this plugin, your website could be vulnerable to attacks from these hackers.

Detected in:

The Plus Addons for Elementor fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.