CVE-2023-6525

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Mar 16, 2024
Updated: Jan 8, 2025
CWE ID 79

Summary

CVE-2023-6525 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the ElementsKit Elementor addons plugin for WordPress. This issue, present in all versions up to 3.0.3, permits authenticated attackers with editor-level access to inject malicious scripts into progress bar element attributes. Consequently, these scripts execute whenever a user views an injected page, posing a significant threat to multi-site installations and those with unfiltered_html disabled. The cause of the vulnerability lies in insufficient input sanitization and output escaping, which enables attackers to exploit this weakness and compromise the affected website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share