← Back to CVE List

CVE-2022-4953

Published: 2023-08-14T20:15Z
Last Modified: 2024-11-21T07:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt