Critical Vulnerability Information Vulnerability Overview CVE ID: CVE-2023-6650 CVSS Score: 6.4 (Medium) Public Release Date: June 26, 2023 Last Updated: June 27, 2023 Researcher: steelthlooper Description The Pack Elementor add-on plugin, in versions <= 2.1.3, is affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability is triggered via the parameter, due to insufficient input validation and output escaping. As a result, authenticated attackers with contributor-level or higher privileges can inject malicious scripts. Reference Links plugins.trac.wordpress.org plugins.trac.wordpress.org plugins.trac.wordpress.org plugins.trac.wordpress.org plugins.trac.wordpress.org Vulnerability Details Software Type: Plugin Software Slug: the-pack-addon (View on WordPress.org) Fixed?: No Mitigation: No known patch is currently available. Organizations should consider mitigation strategies based on their risk tolerance, which may include uninstalling the affected software and seeking alternatives. Affected Versions: <= 2.1.3