CVE-2023-34012: WordPress Premium Addons PRO Plugin <= 2.8.24 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premium Addons for Elementor Premium Addons PRO plugin <= 2.8.24 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Premium Addons PRO Pluginto a version that resolves this vulnerability.Fixed in 2.8.25
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-34012.
What is the title of this vulnerability?
The title of this vulnerability is 'Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premium Addons for Elementor Premium Addons PRO plugin <= 2.8.24 versions.'
What is the severity of CVE-2023-34012?
The severity of CVE-2023-34012 is high with a severity value of 6.1.
What software versions are affected by CVE-2023-34012?
The Premium Addons for Elementor Premium Addons PRO plugin versions <= 2.8.24 are affected by CVE-2023-34012.
How do I fix CVE-2023-34012?
To fix CVE-2023-34012, you should update the Premium Addons for Elementor Premium Addons PRO plugin to a version higher than 2.8.24.