---
title: "CVE-2021-24891"
canonical: "https://kb.cynergy.app/space/MD/923632057/CVE-2021-24891"
format: markdown
---
**Description**

Certain versions of [Website Builder](https://cve.report/software/elementor/website_builder) from [Elementor](https://cve.report/vendor/elementor) contain the following vulnerability:

The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitize or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.


**Published On**

11/23/2021

**Updated On**

12/15/2021

**Trending**

FALSE

**CWE**

<u>[CWE-79](http://cwe.mitre.org/data/definitions/79.html)</u>

**Exploit**

`https://[yourtld.com]/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoibnVsbCIsImh0bWwiOiI8c2NyaXB0PmFsZXJ0KCd4c3MnKTwvc2NyaXB0PiJ9 `

 

**Mitigation:**

![image](media://d2e12a2e-7310-435f-9fbf-e63f463ed394)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- Update to the latest Elementor version