Input validation vulnerability in Stratum – Elementor Widgets 1.6.0

The Stratum – Elementor Widgets plugin for WordPress has a security vulnerability that allows hackers to inject harmful web scripts into pages. This can happen through the plugin’s Advanced Google Maps and Image Hotspot widgets in all versions up to 1.6.0. The problem is caused by a lack of proper protection on user-supplied information. This means that attackers with contributor-level access or higher can insert their own scripts into pages, which will then run whenever someone visits that page.

Detected in:

Stratum – Elementor Widgets fixed vulnerable versions: >= * <= 1.6.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.