Cross-site Scripting Vulnerability in WPBITS Addons for Elementor Page Builder by WPBits
CVE-2024-56285
5.4MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 7 January 2025
Summary
The WPBITS Addons for Elementor Page Builder contains a vulnerability that allows for stored Cross-site Scripting (XSS). This issue arises from improper neutralization of input during web page generation, enabling attackers to inject malicious scripts that can be executed in users' browsers. Versions affected range from n/a through 1.5.1, necessitating immediate attention to secure website environments using this plugin.
Affected Version(s)
WPBITS Addons For Elementor Page Builder <= 1.5.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Robert DeVore (Patchstack Alliance)