• Resolved mullevamshi

    (@mullevamshi)


    Hi Team,

    We are having multiple veracode vulnerabilities in elementor plugin in latest version too. Please find below of some

    CWE 73 External Control of File Name or Path


    Thanks & Regards,

    Vamshi Mulle

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Support Milos

    (@miloss84)

    Hi there,

    Thanks for contacting us and hope you are doing well and having a great day.

    To rule out the possibility of a plugin or theme conflict, please deactivate all your plugins (besides Elementor ). If it solves the issue reactivate them one by one to find the culprit. If it didn’t help, switch your theme (temporarily) to a default WP theme such as Twenty Nineteen and see if it makes any difference.

    Also, this could happen due to our Elementor performance experiments you can try to deactivate them. To deactivate them you can go to Elementor > settings > features

    Performance features currently in the experimental stage are:

    • Element Caching – Elements caching reduces loading times by serving up a copy of an element instead of rendering it fresh every time the page is loaded. When active, Elementor will determine which elements can benefit from static loading – but you can override this.
    • Inline Font Icons – This experiment renders icons as SVGs without loading the Font-Awesome and eicons libraries. Since SVGs are vector-based images which are rendered using the browser’s engine, they do not increase server requests which improves performance

    I am looking forward to hearing back from you soon.

    Kind regards,

    Thread Starter mullevamshi

    (@mullevamshi)

    Hi Milos,
    Thank you for explaining. I can see the performance features are already in deactivate state. PFB screenshot. and still we have those vulnerabilities. Please help


    Regards,
    Vamshi Mulle

    • This reply was modified 10 months ago by mullevamshi.
    Thread Starter mullevamshi

    (@mullevamshi)

    Hi Milos,
    Please help.

    Thread Starter mullevamshi

    (@mullevamshi)

    Hi Team,
    Please help resolving this.
    Thanks

    I’m Sergio from the Elementor Support team.

    Since this is a potential security vulnerability in Elementor, please note that it falls outside the scope of our standard support. However, we take these reports very seriously. You can submit the vulnerability by following the steps in our Bug Bounty Program:

    🔗 https://elementor.com/bug-bounty-programs/

    Thank you for choosing Elementor!

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Veracode vulnerabilities in elementor plugin’ is closed to new replies.