Stored Cross-Site Scripting in Elementor Addons Plugin by Livemesh for WordPress
CVE-2024-1464
5.4MEDIUM
What is CVE-2024-1464?
The Elementor Addons by Livemesh plugin for WordPress is impacted by a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping in the âstyleâ attribute of the Posts Slider widget. This flaw allows authenticated users with contributor-level access and above to inject arbitrary web scripts, compromising the integrity of pages that will execute on access. This vulnerability puts end users at risk whenever they visit affected pages, making it essential for website administrators to address this security issue promptly.
Affected Version(s)
Elementor Addons by Livemesh * <= 8.3.4