CVE-2024-3162: Jeg Elementor Kit <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attributes in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32721 is likely a duplicate of this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3162?
CVE-2024-3162 is considered a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2024-3162?
To mitigate CVE-2024-3162, upgrade the Jeg Elementor Kit plugin to version 2.6.4 or later.
Who is affected by CVE-2024-3162?
All users of the Jeg Elementor Kit plugin for WordPress versions up to and including 2.6.3 are affected by CVE-2024-3162.
What type of vulnerability is CVE-2024-3162?
CVE-2024-3162 is a stored cross-site scripting (XSS) vulnerability.
What can an attacker potentially do with CVE-2024-3162?
An authenticated attacker could exploit CVE-2024-3162 to inject malicious scripts into the web application, affecting users' sessions.