Stored Cross-Site Scripting Vulnerability in Premium Addons for Elementor Plugin
CVE-2024-3885
5.4MEDIUM
What is CVE-2024-3885?
The Premium Addons for Elementor plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping. This weakness allows authenticated attackers, with contributor access or above, to manipulate the subcontainer value parameter. When exploited, these attackers can inject arbitrary web scripts, which will execute in the browsers of users accessing the compromised pages. This issue affects all versions of the plugin up to and including version 4.10.28, therefore it is critical for users to update to the latest version to mitigate this risk.
Affected Version(s)
Premium Addons for Elementor * <= 4.10.28