Stored Cross-Site Scripting Vulnerability in The Plus Addons for Elementor by WPDeveloper
CVE-2024-11829
5.4MEDIUM
Key Information:
- Vendor
- Posimyththemes
- Status
- The Plus Addons For Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
- Vendor
- CVE Published:
- 1 February 2025
Summary
The Plus Addons for Elementor plugin is susceptible to a stored cross-site scripting vulnerability through its Table Widget's searchable_label parameter. This flaw stems from inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level access and above to insert malicious JavaScript code. Consequently, any user visiting a compromised page could execute these scripts, posing significant security risks and affecting the integrity of the website.
Affected Version(s)
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce * <= 6.1.8
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
D.Sim