The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13865
Reference (s):
- https://www.softwaresecured.com/elementor-page-builder-stored-xss/

