Stored Cross-Site Scripting Vulnerability in The Plus Addons for Elementor by WPDeveloper
CVE-2024-11829
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 February 2025
What is CVE-2024-11829?
The Plus Addons for Elementor plugin is susceptible to a stored cross-site scripting vulnerability through its Table Widget's searchable_label parameter. This flaw stems from inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level access and above to insert malicious JavaScript code. Consequently, any user visiting a compromised page could execute these scripts, posing significant security risks and affecting the integrity of the website.
Affected Version(s)
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce * <= 6.1.8