packetstormsecurity.com
http://packetstormsecurity.com/files/174550/WordPress-Elementor-Iframe-Injection.html CVE-2022-4953
MEDIUM
Elementor < 3.5.5 - Iframe Injection
Record summary
CVE-2022-4953 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Elementor Website BuilderDefault status: unaffected | CVE List | Before 3.5.5 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Plugin Elementor 3.5.5 - Iframe InjectionExploitDB exploitby Miguel SantarenoNot analyzed1 file
References
4github.com
https://github.com/elementor/elementor/commit/292fc49e0f979bd52d838f0326d1faaebfa59f5e nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-4953 wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/8273357e-f9e1-44bc-8082-8faab838eda7