Stored Cross-Site Scripting Vulnerability in Premium Addons for Elementor Plugin
CVE-2024-3885
5.4MEDIUM
Summary
The Premium Addons for Elementor plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping. This weakness allows authenticated attackers, with contributor access or above, to manipulate the subcontainer value parameter. When exploited, these attackers can inject arbitrary web scripts, which will execute in the browsers of users accessing the compromised pages. This issue affects all versions of the plugin up to and including version 4.10.28, therefore it is critical for users to update to the latest version to mitigate this risk.
Affected Version(s)
Premium Addons for Elementor * <= 4.10.28
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ngô Thiên An