Showing 1 vulnerability on this page for Starter Templates — Elementor, Gutenberg & Beaver Builder Templates

Signals CISA KEV Ransomware Nuclei
brainstormforce vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Starter Templates — Elementor, Gutenberg & Beaver Builder Templates <= 2.7.0 Authenticated Block Import to Stored XSS

On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to astra-page-elementor-batch-process and the url

CVSS7.6v3.1EPSS0.585%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX