An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15020
Reference (s):
- http://hidden-one.co.in/2020/07/07/cve-2020-1020-stored-xss-on-elementor-wordpress-plugin/
- https://wordpress.org/plugins/elementor/#developers

