Description
The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.
Problem types
CWE-79 Cross-Site Scripting (XSS)
Product status
Any version before 6.3.16
Credits
Tan Nguyen
WPScan
References
wpscan.com/...rability/a9539def-d92b-4117-b36a-17015c578d89/