CVE-2024-30423: WordPress Better Elementor Addons plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability
Published Mar 29, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.3.7.
Affected Software
3 affected components
BetterAddons Better Elementor Addons<=1.3.7
WordPress Better Elementor Addons<=1.3.7
Kitforest Better Elementor Addons Wordpress<1.3.8
Remediation
Information
Update to 1.3.8 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30423?
CVE-2024-30423 has a high severity level due to its potential to allow stored Cross-site Scripting (XSS) attacks.
2
What versions are affected by CVE-2024-30423?
CVE-2024-30423 affects Better Elementor Addons versions up to and including 1.3.7.
3
How do I fix CVE-2024-30423?
To fix CVE-2024-30423, upgrade Better Elementor Addons to a version that is not vulnerable, as detailed by the vendor.
4
What type of vulnerability is CVE-2024-30423?
CVE-2024-30423 is classified as a Cross-site Scripting (XSS) vulnerability.
5
What could happen if CVE-2024-30423 is exploited?
If exploited, CVE-2024-30423 could allow attackers to execute malicious scripts in the context of the user's browser.