---
title: "CVE-2021-24202"
canonical: "https://kb.cynergy.app/space/MD/923730318/CVE-2021-24202"
format: markdown
---
**Description**


Certain versions of [Website Builder](https://cve.report/software/elementor/website_builder) from [Elementor](https://cve.report/vendor/elementor) contain the following vulnerability:

In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘title’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.

**Published On**

4/05/2021

**Updated On**

04/09/2021

**Trending**

FALSE

**CWE**

<u>[CWE-79](http://cwe.mitre.org/data/definitions/79.html)</u>

**Exploit**

[https://wpscan.com/vulnerability/b72bd13d-c8e2-4347-b009-542fc0fe21bb](https://wpscan.com/vulnerability/b72bd13d-c8e2-4347-b009-542fc0fe21bb) 

 

**Mitigation:**

![image](media://3793054c-fc9a-4818-af5b-3dcbbba02d2b)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Update to the latest version of the Elementor plugin

**References**

|  |  |  |
| --- | --- | --- |
| Attention Required! | Cloudflare | [http://wpscan.com](http://wpscan.com)   
<span style="color: #ffffff">**text/html**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |
| Cross-Site Scripting Vulnerabilities in Elementor Impact Over 7 Million Sites | [http://www.wordfence.com](http://www.wordfence.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |