CVE-2023-32241: WordPress Essential Addons for Elementor Pro Plugin <= 5.4.8 is vulnerable to Cross Site Scripting (XSS)
Published Aug 29, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPDeveloper Essential Addons for Elementor Pro plugin <= 5.4.8 versions.
Affected Software
1 affected component
WPDeveloper Essential Addons For Elementor Wordpress<=5.4.8
Remediation
Information
Update to 5.4.9 or a higher version.
Event History
Aug 29, 2023
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32241?
The severity of CVE-2023-32241 is high with a CVSS score of 6.1.
2
How does CVE-2023-32241 affect WPDeveloper Essential Addons for Elementor Pro plugin?
CVE-2023-32241 affects WPDeveloper Essential Addons for Elementor Pro plugin version 5.4.8 and below.
3
What is a Cross-Site Scripting (XSS) vulnerability?
Cross-Site Scripting (XSS) vulnerability is a security flaw that allows attackers to inject malicious scripts into web pages viewed by users.
4
Is authentication required to exploit CVE-2023-32241?
No, authentication is not required to exploit CVE-2023-32241.
5
How can I fix CVE-2023-32241?
To fix CVE-2023-32241, update WPDeveloper Essential Addons for Elementor Pro plugin to version 5.4.9 or above.