CVE-2024-24831: WordPress Premium Addons for Elementor plugin <= 4.10.16 - Cross Site Scripting (XSS) vulnerability
Published Feb 10, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.16.
Affected Software
1 affected component
Leap13 Premium Addons For Elementor Wordpress<4.10.17
Remediation
Information
Update to 4.10.17 or a higher version.
Event History
Feb 10, 2024
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24831?
CVE-2024-24831 is classified as a stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-24831?
To fix CVE-2024-24831, update Premium Addons for Elementor to version 4.10.17 or later.
3
Which versions of Premium Addons for Elementor are affected by CVE-2024-24831?
CVE-2024-24831 affects Premium Addons for Elementor versions from n/a through 4.10.16.
4
What impact does CVE-2024-24831 have on web applications?
CVE-2024-24831 can allow attackers to execute malicious scripts in the context of a user's session.
5
Is authentication required to exploit CVE-2024-24831?
No, CVE-2024-24831 can be exploited without authentication, allowing unauthenticated users to execute their scripts.