Elementor · The Plus Addons For Elementor · CVE-2024-5583
**Name of the Vulnerable Software and Affected Versions**
The Plus Addons for Elementor versions up to, and including, 5.6.2
**Description**
The issue is related to Stored Cross-Site Scripting via the `carousel direction` parameter of the testimonials widget. This is due to insufficient input sanitization and output escaping on user-supplied attributes, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages. These scripts will execute whenever a user accesses an injected page.
**Recommendations**
For versions up to, and including, 5.6.2, update to a version that addresses the insufficient input sanitization and output escaping issue. As a temporary workaround, consider restricting access to the testimonials widget or disabling the `carousel direction` parameter to minimize the risk of exploitation.