Security Advisory

CVE-2022-4953

6.1
MEDIUM

Vulnerability Description

The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
Published Date August 14, 2023
Official Source NIST NVD Advisory