Stored Cross-Site Scripting Vulnerability in Master Addons Plugin
CVE-2024-5542
7.2HIGH
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 7 June 2024
What is CVE-2024-5542?
The Master Addons for Elementor plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit Stored Cross-Site Scripting through the Navigation Menu widget of its Mega Menu extension. This issue arises from inadequate sanitization and escaping of user-supplied attributes, enabling the injection of arbitrary web scripts. When a page is accessed, these scripts can execute, posing significant risks to users and the integrity of the website.
Affected Version(s)
Master Addons For Elementor β Widgets, Extensions, Theme Builder, Popup Builder & Template Kits 0 <= 2.0.6.1