Cross-site Scripting Vulnerability in Themesflat Addons for Elementor
CVE-2024-49310

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 October 2024

What is CVE-2024-49310?

An XSS vulnerability exists in the Themesflat Addons for Elementor that allows attackers to exploit improper neutralization of user inputs during web page generation. This can lead to stored XSS, where malicious scripts are injected and executed in the context of users' browsers, potentially compromising session information and sensitive data. Users running versions n/a through 2.2.0 of the plugin are advised to check for updates and implement security measures to mitigate potential attacks.

Affected Version(s)

themesflat-addons-for-elementor 0 <= 2.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.