Input validation vulnerability in Exclusive Addons for Elementor 2.6.9.6

The Exclusive Addons for Elementor plugin for WordPress has a security issue that can allow hackers to inject harmful scripts into web pages. This can happen through the Team Member widget and affects all versions up to 2.6.9.6. This vulnerability is caused by the plugin not properly filtering and protecting the ‘url’ attribute provided by users. It can only be exploited by users with contributor-level access or higher.

Detected in:

Exclusive Addons for Elementor fixed vulnerable versions: >= * <= 2.6.9.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.