---
title: "CVE-2021-24201"
canonical: "https://kb.cynergy.app/space/MD/923664798/CVE-2021-24201"
format: markdown
---
**Description**


Certain versions of [Website Builder](https://cve.report/software/elementor/website_builder) from [Elementor](https://cve.report/vendor/elementor) contain the following vulnerability:

In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

**Published On**

4/05/2021

**Updated On**

04/09/2021

**Trending**

FALSE

**CWE**

<u>[CWE-79](http://cwe.mitre.org/data/definitions/79.html)</u>

**Exploit**

[https://wpscan.com/vulnerability/9647f516-b130-4cc8-85fb-2e69b034ced0](https://wpscan.com/vulnerability/9647f516-b130-4cc8-85fb-2e69b034ced0) 

 

**Mitigation:**

![image](media://f0c9e48b-ba37-49dd-8945-a74a3e92d038)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Update to the latest version of the Elementor plugin

**References**

|  |  |  |
| --- | --- | --- |
| Attention Required! | Cloudflare | [http://wpscan.com](http://wpscan.com)   
<span style="color: #ffffff">**text/html**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |
| Cross-Site Scripting Vulnerabilities in Elementor Impact Over 7 Million Sites | [http://www.wordfence.com](http://www.wordfence.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |