---
title: "CVE-2021-24205"
canonical: "https://kb.cynergy.app/space/MD/923730248/CVE-2021-24205"
format: markdown
---
**Description**

Specific versions of [Website Builder](https://cve.report/software/elementor/website_builder) from [Elementor](https://cve.report/vendor/elementor) contain the following vulnerability:

In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible HTML tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

**Published On**

4/05/2021

**Updated On**

04/09/2021

**Trending**

FALSE

**CWE**

<u>[CWE-79](http://cwe.mitre.org/data/definitions/79.html)</u>

**Exploit**

[https://wpscan.com/vulnerability/ef23df6d-e265-44f6-bb94-1005b16d34d9](https://wpscan.com/vulnerability/ef23df6d-e265-44f6-bb94-1005b16d34d9) 

 

**Mitigation:**

![image](media://71bd5acb-5069-4711-8063-0b82dc750464)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Update to the latest version of the Elementor plugin

**References**

|  |  |  |
| --- | --- | --- |
| Attention Required! | Cloudflare | [http://wpscan.com](http://wpscan.com)   
<span style="color: #ffffff">**text/html**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |
| Cross-Site Scripting Vulnerabilities in Elementor Impact Over 7 Million Sites | [http://www.wordfence.com](http://www.wordfence.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |