Cross-site Scripting Vulnerability in Move Addons for Elementor by MoveAddons
CVE-2024-56254

5.4MEDIUM

Key Information:

Vendor
Moveaddons
Status
Move Addons For Elementor
Vendor
CVE Published:
2 January 2025

Summary

The vulnerability related to improper neutralization of input during web page generation, specifically a stored Cross-site Scripting (XSS) vulnerability, exists in Move Addons for Elementor. Attackers can exploit this weakness to inject malicious scripts that are stored on the server and executed whenever the affected web pages are accessed by users. This poses a significant threat, as it allows intruders to manipulate web content and potentially hijack user sessions, steal confidential information, or perform unauthorized actions on behalf of users. This issue affects versions of Move Addons for Elementor up to 1.3.6, making timely updates crucial for maintaining security.

Affected Version(s)

Move Addons for Elementor <= 1.3.6

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.