Input validation vulnerability in Classy Addons for Elementor 1.2.7

A plugin called “Classy Addons for Elementor” used for WordPress websites has a security issue. This problem, called Stored Cross-Site Scripting, affects versions 1.2.7 and below. It happens because the plugin does not properly clean up information that is entered and displayed on the website. This means that someone who is logged into the website and has contributor-level or higher privileges can add their own malicious code onto a page. This code will then run whenever someone visits that page.

Detected in:

Classy Addons for Elementor open vulnerable versions: >= * <= 1.2.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.