CVE-2022-29455
MEDIUM 6.1EPSS 23.7%
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 4.7 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 23.68% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- medium · CWE-79
- Published
- 2022-06-13
- Updated
- 2026-04-28
Proof-of-concept exploits (7)
- https://rotem-bar.com/hacking-65-million-websites-greater-cve-2022-29455-elementor
- 0xc4t/CVE-2022-294553★ · 2023-02-24
- 0xkucing/CVE-2022-294553★ · 2023-02-24
- GULL2100/Wordpress_xss-CVE-2022-294554★ · 2022-07-05
- akhilkoradiya/CVE-2022-2945517★ · 2022-09-05
- varelsecurity/CVE-2022-294553★ · 2023-02-24
- yaudahbanh/CVE-2022-294552★ · 2023-01-05