Millions of WordPress sites affected by vulnerabilities in Elementor add-on plugins

Wordfence security researchers discovered that virtually every plugin tested that adds functionality to Elementor had a vulnerability. Many of the contacted plugin publishers updated their plugins but not all of them responded, including premium plugins.

The Elementor page builder plugin itself patched a similar vulnerability in February 2021.

This vulnerability affects add-on plugins for Elementor that are created by third parties.

According to Wordfence:

“We found the same vulnerabilities in nearly every plugin we reviewed that adds additional elements to the Elementor page builder.”

So it seems that this vulnerability is fairly widespread within the third party plugins that are add-ons to Elementor

#wordpress #elementor

Vulnerabilities in 17+ Elementor Add-on Plugins for WordPress
2.15 GEEK