Cross-site Scripting Vulnerability in WPBITS Addons for Elementor Page Builder by WPBits
CVE-2024-56285

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
7 January 2025

Summary

The WPBITS Addons for Elementor Page Builder contains a vulnerability that allows for stored Cross-site Scripting (XSS). This issue arises from improper neutralization of input during web page generation, enabling attackers to inject malicious scripts that can be executed in users' browsers. Versions affected range from n/a through 1.5.1, necessitating immediate attention to secure website environments using this plugin.

Affected Version(s)

WPBITS Addons For Elementor Page Builder <= 1.5.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert DeVore (Patchstack Alliance)
.