Input validation vulnerability in The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce 6.2.7

The Plus Addons plugin for WordPress, which works with the Elementor Page Builder, is at risk for a type of attack called Stored Cross-Site Scripting. This is because the plugin does not properly clean up user input and output, leaving it vulnerable to malicious scripts being inserted into pages. This can be exploited by attackers with certain levels of access to the site, allowing them to execute harmful scripts whenever someone views the affected page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.