CVE-2024-29108: WordPress Happy Addons for Elementor plugin <= 3.10.1 - Cross Site Scripting (XSS) vulnerability
Published Mar 19, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.
Affected Software
1 affected component
Leevio Happy Addons For Elementor Wordpress<=3.10.1
Remediation
Information
Update to 3.10.2 or a higher version.
Event History
Mar 19, 2024
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29108?
The severity of CVE-2024-29108 is classified as high due to its potential for Stored Cross-site Scripting attacks.
2
How do I fix CVE-2024-29108?
To fix CVE-2024-29108, upgrade the Happy Addons for Elementor plugin to version 3.10.2 or higher.
3
What versions of Happy Addons for Elementor are affected by CVE-2024-29108?
CVE-2024-29108 affects Happy Addons for Elementor versions up to and including 3.10.1.
4
What type of vulnerability is CVE-2024-29108?
CVE-2024-29108 is a Stored Cross-site Scripting (XSS) vulnerability.
5
Can CVE-2024-29108 lead to data breaches?
Yes, CVE-2024-29108 can potentially lead to data breaches if an attacker exploits the Stored XSS vulnerability.