Cross-Site Scripting Vulnerability in WPDeveloper's Essential Addons for Elementor Plugin
CVE-2024-56063
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2024
What is CVE-2024-56063?
The vulnerability manifests as an improper neutralization of input during web page generation, leading to a Stored Cross-Site Scripting (XSS) flaw in WPDeveloper's Essential Addons for Elementor plugin. It allows attackers to inject malicious scripts into web pages viewed by other users. This issue affects versions from n/a up to and including 6.0.7, posing a potential risk of unauthorized actions being executed on behalf of unsuspecting users. It is crucial for site owners to update the plugin to mitigate the risk of exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Essential Addons for Elementor <= 6.0.7
References
CVSS V3.1
Timeline
Vulnerability published