Record summary

CVE-2021-24258 has a selected CVSS score of 5.4 (medium).

Description

The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 19, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List2.2.0 to < 2.2.0affected
CVE List2.2.0 to < 2.2.0affected
VulnCheckVersion data not supplied

References

3