First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.93.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Unlimited Elements For Elementor | <1.5.95 | |
Unlimited Elements for Elementor | <=1.5.93 | |
WordPress Unlimited Elements For Elementor | <=1.5.93 |
Update to 1.5.94 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29792 has a high severity rating due to its potential for reflected cross-site scripting (XSS) attacks.
To mitigate CVE-2024-29792, update Unlimited Elements For Elementor to version 1.5.96 or higher.
CVE-2024-29792 is an improper neutralization of input during web page generation vulnerability, commonly known as reflected XSS.
CVE-2024-29792 affects Unlimited Elements For Elementor versions up to and including 1.5.93.
CVE-2024-29792 can allow attackers to inject malicious scripts into web pages viewed by users, potentially leading to data theft or session hijacking.