First published: Sun Apr 07 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.93.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Royal Elementor Addons | <1.3.94 |
Update to 1.3.95 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31236 is classified as a Stored XSS vulnerability, which is typically of high severity due to its potential for exploitation.
To fix CVE-2024-31236, update the Royal Elementor Addons plugin to version 1.3.94 or later.
CVE-2024-31236 affects Royal Elementor Addons versions prior to 1.3.94 on WordPress.
Stored XSS in CVE-2024-31236 refers to the vulnerability where malicious scripts can be injected and stored on the server, affecting all users.
If unable to update, consider disabling the Royal Elementor Addons plugin until a secure version can be implemented.