---
title: "CVE-2021-24206"
canonical: "https://kb.cynergy.app/space/MD/923632101/CVE-2021-24206"
format: markdown
---
**Description**

Specific versions of [Website Builder](https://cve.report/software/elementor/website_builder) from [Elementor](https://cve.report/vendor/elementor) contain the following vulnerability:

In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible HTML tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

**Published On**

05/01/2022

**Updated On**

10/28/2022

**Trending**

FALSE

**CWE**

<u>[CWE-79](http://cwe.mitre.org/data/definitions/79.html)</u>

**Exploit**

 [https://wpscan.com/vulnerability/2f66efd9-7d55-4f33-9109-3cb583a0c309](https://wpscan.com/vulnerability/2f66efd9-7d55-4f33-9109-3cb583a0c309) 

**Mitigation:**

![image](media://d1f1b6d3-e4cf-4055-81ca-27d9b9f97280)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- Update to the latest version of the Elementor Plugin

**References**

|  |  |  |
| --- | --- | --- |
| Attention Required! | Cloudflare | [http://wpscan.com](http://wpscan.com)   
<span style="color: #ffffff">**text/html**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |
| Cross-Site Scripting Vulnerabilities in Elementor Impact Over 7 Million Sites | [http://www.wordfence.com](http://www.wordfence.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |