1
Update DOMPurify
Source: elementor/elementor#37355 · opened by @brownemint
Describe the Problem My customer uses AppCheck to scan their website on a monthly basis. This month, it flagged 30 CVE's related to the version of DOMPurify that the Elementor plugin is using (DOMPurify 3.3.0). 1. Cure53 Dompurify v3.3.0 - Out of Date Software Version Detected 2. Cure53 DOMPurify 3.x < v3.4.9 - Failure or Bypass of Security Protection Mechanism (CVE-2026-65899) 3. Cure53 DOMPurify < v3.4.0 - Cross-Site Scripting ('XSS') Vulnerability (CVE-2026-65911) 4. Cure53 DOMPurify <= v3.4.6 - Cross-Site Scripting ('XSS') Vulnerability (CVE-2026-65901) 5. Cure53 DOMPurify < v3.4.11 - Stored (Persistent) Cross-Site Scripting ('XSS') Vulnerability (CVE-2026-65898) 6. Cure53 DOMPurify < v3.4.0 - Improper Enforcement of Behavioral Workflow (CVE-2026-65903) 7. Cure53 DOMPurify < v3.4.7 - Trust Boundary Violation Vulnerability (CVE-2026-65902) 8. Cure53 DOMPurify < v3.3.2 - Cross-Site Scripting ('XSS') Vuln…
No pledges yet. Be the first to back this.
Comments
Similar requests
Feature Request: Add lock/disable to "Update" page button on Elementor editor screen
1 vote · 0 comments
Remove the stupid update alert banner
9 votes · 0 comments
WP Dashboard Notices: Stop Showing the 'The Version Was Updated Successfully!' Message
1 vote · 0 comments
⏳ 🔗 ACF / ACF Pro Field Editing Directly in the Elementor Editor
7 votes · 0 comments
Update 3.25.0 brought back SEO-unfriendly slag for TOC widget links
3 votes · 0 comments
No comments yet.