PT-2024-34981 · Elementor · Dynamic Post Grid Elementor Addon

Gab

·

Published

2024-11-19

·

Updated

2024-11-23

·

CVE-2024-51852

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Dynamic Post Grid Elementor Addon versions 1.0.0 through 1.0.6
Description The issue affects the Dynamic Post Grid Elementor Addon, allowing DOM-Based XSS due to improper neutralization of input during web page generation. This is a high-severity XSS vulnerability. Users are urged to update to the latest version to mitigate risks.
Recommendations For versions 1.0.0 through 1.0.6, update to the latest version to secure the site and mitigate the risks associated with this issue. As a temporary workaround, consider restricting access to the addon until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51852

Affected Products

Dynamic Post Grid Elementor Addon