Stored Cross-Site Scripting Vulnerability in Premium Addons for Elementor Plugin
CVE-2024-3885

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 May 2024

Summary

The Premium Addons for Elementor plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping. This weakness allows authenticated attackers, with contributor access or above, to manipulate the subcontainer value parameter. When exploited, these attackers can inject arbitrary web scripts, which will execute in the browsers of users accessing the compromised pages. This issue affects all versions of the plugin up to and including version 4.10.28, therefore it is critical for users to update to the latest version to mitigate this risk.

Affected Version(s)

Premium Addons for Elementor * <= 4.10.28

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ngô Thiên An
.