Stored Cross-Site Scripting in Essential Addons for Elementor
CVE-2024-2650

6.4MEDIUM

What is CVE-2024-2650?

The Essential Addons for Elementor plugin, widely used for creating custom templates and enhancing WooCommerce functionality within WordPress, is susceptible to Stored Cross-Site Scripting. This vulnerability arises from inadequate sanitization of user inputs via the alignment parameter in the Woo Product Carousel widget. As a result, authenticated users with contributor-level access or higher can insert malicious scripts into web pages, leading to potential exploitation when other users visit the affected pages. This situation emphasizes the necessity for stringent input validation and output escaping to safeguard against such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders * <= 5.9.11

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ngô Thiên An
Son Tran
.