S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24891 Scanner

CVE-2021-24891 scanner - Cross-Site Scripting (XSS) vulnerability in Elementor Website Builder plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24891
6.1
CVSS

The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Elementor Website Builder
AFFECTED< 3.4.8SAFE ✓≥ 3.4.8
Updated Aug 21, 2026View on NVD →
Detail

The Elementor Website Builder Wordpress Plugin is a popular tool used to create stunning websites. This plugin provides a simple drag-and-drop interface that helps users design and build their website layouts with ease. Millions of websites around the world are powered by the Elementor Website Builder Plugin.

However, recently, a security vulnerability was detected in the plugin. The vulnerability code is CVE-2021-24891. This vulnerability can be exploited to create a malicious hash that can be used to append user input. Unfortunately, the Elementor Website Builder Plugin does not sanitise or escape this input, resulting in a DOM cross-site scripting issue.

When exploited, the CVE-2021-24891 vulnerability can allow attackers to inject malicious code into websites using the plugin. Attackers can then use this code to steal sensitive information, such as login credentials or financial data, from unsuspecting users. The vulnerability can also be used to take control of the website and execute malicious activities.

At s4e.io, we offer pro features that help users quickly identify vulnerabilities in their digital assets. We believe that in today's world, proactive measures must be taken to protect digital assets from malicious actors. Our platform can scan for vulnerabilities and identify security gaps that need to be addressed, leaving you with peace of mind. Don't hesitate to try our services today to secure your digital assets.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-24891 vulnerability, users can follow these precautions:

  • Update the Elementor Website Builder Plugin to the latest version as it includes necessary security updates.
  • Use security plugins that can help identify vulnerabilities, such as SecurityForEveryone.com.
  • Use strong passwords and two-factor authentication to prevent unauthorised access.
  • Install web application firewalls to stop attacks before they reach the server.
  • Carefully review third-party plugins and themes used on the website.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.