CyberRota Analysis
AI-GeneratedThe Sina Extension for Elementor WordPress plugin prior to version 3.10.4 is vulnerable to Stored Cross-Site Scripting due to inadequate escaping of a Table widget setting in HTML attributes. This flaw allows users with Contributor roles and higher to inject malicious scripts, potentially compromising site security and user data. WordPress site administrators, especially those using the affected plugin, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.