What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor Pro allows Reflected XSS.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.
Explanation of Vulnerability in Simple Terms
02Summary
Piotnet Addons For Elementor Pro versions up to 7.1.17 contain a cross-site scripting vulnerability that allows attackers to inject malicious scripts into the site. An attacker can craft a malicious link that, when clicked by a site visitor, executes JavaScript in their browser. This can lead to session hijacking, credential theft, or malware distribution. Update to a version newer than 7.1.17.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in visitors' browsers via a crafted link.
Potential impact on your site
04Site Impact
Visitors' sessions, credentials, or personal data could be compromised if they click a malicious link.
Conditions required to exploit
05Prerequisites
A site visitor must click an attacker-supplied link while logged in or visiting the site.
Key dates
06Disclosure timeline
April 29, 2024
CVE published
April 28, 2026
Record updated