Stored Cross-Site Scripting Vulnerability in Elementor Plugin
CVE-2024-9888
Key Information:
- Vendor
- Elementinvader
- Status
- Elementinvader Addons For Elementor
- Vendor
- CVE Published:
- 16 October 2024
Summary
The ElementInvader Addons for Elementor plugin for WordPress presents a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the plugin's contact form widget redirect URL. This flaw enables authenticated users with a contributor-level access or higher to insert arbitrary web scripts into pages. Such scripts execute whenever a user accesses these modified pages, potentially leading to unauthorized actions and breaches of user data security. Mitigation strategies include ensuring proper input validation and output encoding to prevent script injection.
Affected Version(s)
ElementInvader Addons for Elementor * <= 1.2.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved