PT-2024-36542 · WordPress · Premium Addons For Elementor

Wesley

·

Published

2024-06-12

·

Updated

2025-01-15

·

CVE-2024-5553

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Premium Addons for Elementor plugin for WordPress versions up to, and including, 4.10.33
Description The issue is related to DOM-Based Stored Cross-Site Scripting due to insufficient input sanitization and output escaping. This allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages. The scripts will execute when a user accesses and edits an injected element and clicks the element with the mouse scroll wheel.
Recommendations For versions up to, and including, 4.10.33, update to a version later than 4.10.33 to resolve the issue. As a temporary workaround, consider restricting access to elements that can be edited by users with Contributor-level access and above until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-5553

Affected Products

Premium Addons For Elementor