S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-29455 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Elementor Website Builder plugin for WordPress affects v. 3.5.5 and before.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-29455
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Elementor Website Builder (WordPress plugin)by Elementor
<= 3.5.5
Updated Aug 22, 2026View on NVD →
Detail

Elementor Website Builder is a popular WordPress plugin used for creating and designing websites in an easy and intuitive manner. With over 5 million active installations, this plugin offers a user-friendly interface that allows users to create custom designs without any coding skills. The drag and drop feature makes the process of website creation faster and uncomplicated. Elementor offers premium features like the ability to create pop-ups, forms, and widgets, and many others.

CVE-2022-29455 is a DOM-based Reflected Cross-Site Scripting (XSS) vulnerability detected in Elementor Website Builder plugin versions <= 3.5.5. This vulnerability occurs when data entered by a web user gets reflected back to the user on the same webpage, and malicious attackers can exploit this by injecting scripts that can execute unauthorized commands. In simpler terms, an attacker can use the vulnerability to execute scripts on the user's browser, leading to unauthorized actions on the website.

This vulnerability can lead to various consequences when exploited, such as stealing sensitive user information, spreading malware, hijacking the user's session, presenting fake login forms to steal the user's credentials, and redirecting the user to malicious websites. The consequences of this vulnerability can be severe and can significantly harm the website's users and owners.

With the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform offers real-time monitoring of vulnerabilities, alerts for newly detected vulnerabilities, and seamless integration with multiple CMS platforms like WordPress, Drupal, and Magento. Thanks to these features, users can stay ahead of cyber threats and protect their digital assets from potential attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update to the latest version of the Elementor Website Builder plugin.
  • Install a web application firewall to prevent XSS attacks.
  • Use Content Security Policy (CSP) headers to restrict the sources of executable scripts.
  • Avoid using untrusted third-party plugins and scripts.
  • Use HTTPS protocol for secure communication.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.