Input validation vulnerability in Mega Elements – Addons for Elementor 1.2.6

The Mega Elements plugin for WordPress has a security issue called Stored Cross-Site Scripting. This can happen in versions 1.2.6 and below because the plugin does not properly clean or filter the information that is inputted and outputted. This means that attackers who have contributor-level access or higher can insert their own malicious code into pages, and when a user views that page, the code will be executed.

Detected in:

Mega Elements – Addons for Elementor fixed vulnerable versions: >= * <= 1.2.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.