Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24145 | The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts. |
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Elementor Website Builder <= 2.9.7 - Authenticated Stored Cross-Site Scripting |
Sat, 21 Dec 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:48:59.876Z
Reserved: 2023-06-06T12:37:02.385Z
Link: CVE-2020-36703
Updated: 2024-08-04T17:37:05.251Z
Status : Modified
Published: 2023-06-07T02:15:11.327
Modified: 2026-04-08T18:17:06.413
Link: CVE-2020-36703
No data.
OpenCVE Enrichment
No data.
EUVD