CVE-2024-29792: WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.93.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29792?
CVE-2024-29792 has a high severity rating due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2024-29792?
To mitigate CVE-2024-29792, update Unlimited Elements For Elementor to version 1.5.96 or higher.
What type of vulnerability is CVE-2024-29792?
CVE-2024-29792 is an improper neutralization of input during web page generation vulnerability, commonly known as reflected XSS.
Which versions of Unlimited Elements For Elementor are affected by CVE-2024-29792?
CVE-2024-29792 affects Unlimited Elements For Elementor versions up to and including 1.5.93.
What impact can CVE-2024-29792 have on users?
CVE-2024-29792 can allow attackers to inject malicious scripts into web pages viewed by users, potentially leading to data theft or session hijacking.