PT-2024-35741 · WordPress · The Plus Addons For Elementor Page Builder

Wesley

·

Published

2024-06-20

·

Updated

2024-07-17

·

CVE-2024-5344

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Plus Addons for Elementor Page Builder plugin for WordPress versions up to, and including, 5.5.6
Description The issue is related to Reflected Cross-Site Scripting via the forgoturl attribute within the plugin's WP Login & Register widget. This is due to insufficient input sanitization and output escaping, making it possible for unauthenticated attackers to inject arbitrary web scripts in pages. These scripts can execute if an attacker can trick a user into performing an action such as clicking on a link.
Recommendations For versions up to, and including, 5.5.6, update to a version later than 5.5.6 to resolve the issue. As a temporary workaround, consider restricting access to the WP Login & Register widget until a patch is available. Avoid using the forgoturl attribute in the affected widget until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-5344

Affected Products

The Plus Addons For Elementor Page Builder