CVE-2022-4953 is a medium-severity iframe injection vulnerability affecting the Elementor Website Builder WordPress plugin prior to version 3.5.5. It allows unauthenticated attackers to inject malicious iframes into a website by manipulating user-controlled URLs, potentially leading to information disclosure or cross-site scripting. While not actively exploited in the wild and not on the CISA KEV catalog, a public exploit (EDB-51716) exists, and its FAUCET Risk Score of 88/100 indicates a significant potential risk despite low community discussion and media coverage. Organizations using affected Elementor versions should update immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.5CPE matchmatch criteria | cpe:2.3:a:elementor:website_builder:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.