Arbitrary Script Injection Vulnerability in Visualmodo Elements Plugin
CVE-2024-11095
6.4MEDIUM
What is CVE-2024-11095?
The Visualmodo Elements plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability. This issue arises from inadequate input sanitization and output escaping within the plugin's handling of SVG file uploads via the REST API. Authenticated users with Author-level access or higher can exploit this vulnerability to inject arbitrary scripts into pages, potentially leading to malicious code execution whenever a user accesses the compromised SVG file. It is crucial for website owners using this plugin to evaluate their installation for vulnerabilities to safeguard against potential attacks.
Affected Version(s)
Visualmodo Elements * <= 1.0.2