CVE-2024-30177: WordPress Exclusive Addons for Elementor plugin <= 2.6.8 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30177?
CVE-2024-30177 is classified as a Stored Cross-Site Scripting (XSS) vulnerability in Exclusive Addons for Elementor.
How do I fix CVE-2024-30177?
To mitigate CVE-2024-30177, update Exclusive Addons for Elementor to version 2.6.9 or later.
What versions of Exclusive Addons Elementor are affected by CVE-2024-30177?
CVE-2024-30177 affects all versions of Exclusive Addons Elementor from n/a up to and including 2.6.8.
Can CVE-2024-30177 lead to data breaches?
Yes, this vulnerability can allow attackers to inject malicious scripts that compromise user data and session information.
Is user input related to CVE-2024-30177?
Yes, CVE-2024-30177 involves improper neutralization of user input during web page generation, leading to potential XSS attacks.