PT-2024-34772 · Metricthemes · Metricthemes Header Footer Composer For Elementor

Michael

·

Published

2024-11-09

·

Updated

2024-11-12

·

CVE-2024-51629

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions MetricThemes Header Footer Composer for Elementor versions 1.0.0 through 1.0.4
Description The issue is related to an Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This is a DOM-Based XSS vulnerability, which allows remote attacks.
Recommendations For versions 1.0.0 through 1.0.4, update the plugin immediately to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the plugin until a patch is available. Monitor for potential exploits and update the plugin as soon as possible to prevent remote attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51629

Affected Products

Metricthemes Header Footer Composer For Elementor