CVE-2024-2028: Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Covid-19 Stats Widget
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 Stats Widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2028?
CVE-2024-2028 has been classified as a significant security vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2028?
To fix CVE-2024-2028, update the Exclusive Addons for Elementor plugin to the latest version beyond 2.6.9.
Who is affected by CVE-2024-2028?
CVE-2024-2028 affects all users of the Exclusive Addons for Elementor plugin on WordPress up to and including version 2.6.9.
What kind of attack does CVE-2024-2028 enable?
CVE-2024-2028 enables authenticated attackers to execute Stored Cross-Site Scripting attacks through the Covid-19 Stats Widget.
Is input sanitization an issue in CVE-2024-2028?
Yes, insufficient input sanitization and output escaping are the primary causes of CVE-2024-2028.