CVE-2024-32505: WordPress ElementsKit Elementor addons plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability
Published Apr 17, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor ElementsKit Elementor addons Lite elementskit-lite.This issue affects ElementsKit Elementor addons Lite: from n/a through <= 3.0.6.
Affected Software
3 affected components
Wpmet ElementsKit Elementor addons<=3.0.6
WordPress ElementsKit Elementor addons<=3.0.6
Wpmet Elements Kit Elementor Addons Wordpress<3.0.7
Remediation
Information
Update to 3.0.7 or a higher version.
Event History
Apr 17, 2024
CVE Published
via MITRE·09:54 AM
Data Sourced
via MITRE·09:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32505?
CVE-2024-32505 has been classified as a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS).
2
How do I fix CVE-2024-32505?
To fix CVE-2024-32505, update the ElementsKit Elementor addons to the latest version beyond 3.0.6.
3
Which versions of ElementsKit Elementor addons are affected by CVE-2024-32505?
CVE-2024-32505 affects all versions of ElementsKit Elementor addons up to and including 3.0.6.
4
What type of vulnerability is CVE-2024-32505?
CVE-2024-32505 is a Cross-site Scripting (XSS) vulnerability that allows for stored attacks.
5
Who is impacted by CVE-2024-32505?
Users of Wpmet ElementsKit Elementor addons versions up to 3.0.6 are impacted by CVE-2024-32505.