Stored Cross-Site Scripting vulnerability in Best Elementor Addons plugin
CVE-2024-9068
5.4MEDIUM
What is CVE-2024-9068?
The OneElements – Best Elementor Addons plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping during the handling of SVG file uploads. This flaw permits authenticated users with Author-level access or higher to inject malicious web scripts into the application. These scripts may then execute in the context of a user’s session when the SVG file is accessed, potentially undermining the integrity and security of the affected WordPress site.