CVE-2024-10980: Element Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10980?
CVE-2024-10980 has a medium severity rating due to its potential for cross-site scripting vulnerabilities.
How do I fix CVE-2024-10980?
To fix CVE-2024-10980, update the Element Pack Elementor Addons plugin to version 5.10.3 or later.
What are the potential impacts of CVE-2024-10980?
The potential impacts of CVE-2024-10980 include exploitation through cross-site scripting, leading to unauthorized access or actions by users.
Which versions are affected by CVE-2024-10980?
CVE-2024-10980 affects all versions of the Element Pack Elementor Addons plugin prior to version 5.10.3.
Does CVE-2024-10980 require user interaction for exploitation?
Exploitation of CVE-2024-10980 may require user interaction, such as clicking on a malicious link embedded in the output.