First published: Tue Feb 04 2025(Updated: )
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
HT Mega - Absolute Addons For Elementor | <=2.7.6 | |
WordPress HT Mega | <2.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12597 is considered a critical vulnerability due to its potential for exploitation via Stored Cross-Site Scripting.
CVE-2024-12597 affects all versions of the HT Mega – Absolute Addons For Elementor plugin for WordPress up to and including version 2.7.6.
To fix CVE-2024-12597, update the HT Mega – Absolute Addons For Elementor plugin to the latest version that addresses this vulnerability.
Stored cross-site scripting in CVE-2024-12597 refers to the injection of malicious scripts that are stored on the server and executed when users access affected pages.
CVE-2024-12597 is vulnerable through the 'block_css' and 'inner_css' parameters due to insufficient input sanitization and output escaping.