WordPress Elementor Website Builder plugin before 3.1.4 contains a DOM cross-site scripting vulnerability. It does not sanitize or escape user input appended to the DOM via a malicious hash.
id: CVE-2021-24891
info:
name: WordPress Elementor Website Builder <3.1.4 - Cross-Site Scripting
...