<\/a><\/figure>\n\n\n\nBohu\u017eel, Elementor p\u0159i ulo\u017een\u00ed na stran\u011b serveru, neprov\u00e1d\u00ed kontrolu a u\u017eivatel\u00e9, v\u010detn\u011b redaktora, jsou schopni ulo\u017eit spustiteln\u00fd javascript u postu, nebo str\u00e1nky. <\/p>\n\n\n\n
I kdy\u017e redaktor nem\u00e1 pr\u00e1vo publikovat, sta\u010d\u00ed, aby si \u0161\u00e9fredaktor zobrazil koncept a javascript se spust\u00ed. <\/p>\n\n\n\n
Bohu\u017eel, tato zranitelnost se net\u00fdk\u00e1 jen elementu heading, ale i dal\u0161\u00edch, jako je nejpou\u017e\u00edvan\u011bj\u0161\u00ed prvek – column. Ten akceptuje parametr html_tag a umo\u017e\u0148uje vlo\u017eit inline script, kter\u00fd m\u016f\u017ee nap\u0159\u00edklad na\u010d\u00edst \u0161kodliv\u00fd extern\u00ed js soubor.<\/p>\n\n\n\n
Dal\u0161\u00edmi elementy jsou accordion, icon box a image box. <\/p>\n\n\n\n
Pokud m\u00e1te tedy na webu verzi ni\u017e\u0161\u00ed, jak 3.1.2, nev\u00e1hejte s aktualizac\u00ed. <\/p>\n","protected":false},"excerpt":{"rendered":"
T\u00fdm WordFence objevil p\u0159ed n\u011bkolika dny v\u00e1\u017enou zranitelnost v popul\u00e1rn\u00edm pluginu Elementor, kter\u00fd je v sou\u010dasn\u00e9 dob\u011b instalov\u00e1n na sedmi milionech web\u016f. Tak jak je zvykem, informoval p\u0159ed publikac\u00ed o zranitelnosti t\u00fdm v\u00fdvoj\u00e1\u0159\u016f Elementoru a ten druh\u00e9ho b\u0159ezna vydal verzi 3.1.2, jen\u017e zranitelnost opravuje. Pokud m\u00e1te na sv\u00e9m webu star\u0161\u00ed verzi, nev\u00e1hejte s aktualizac\u00ed, v\u00fdvoj\u00e1\u0159<\/p>\n","protected":false},"author":1,"featured_media":9469,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-5897","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezpecnost-wordpressu"],"_links":{"self":[{"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/posts\/5897"}],"collection":[{"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/comments?post=5897"}],"version-history":[{"count":0,"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/posts\/5897\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/media\/9469"}],"wp:attachment":[{"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/media?parent=5897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/categories?post=5897"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/affinite.io\/cs\/wp-json\/wp\/v2\/tags?post=5897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}