CVE-2024-32557: WordPress Exclusive Addons for Elementor plugin <= 2.6.9.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32557?
CVE-2024-32557 is classified as a high severity vulnerability due to its potential for enabling stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-32557?
To fix CVE-2024-32557, update Exclusive Addons Elementor to the latest version that is beyond 2.6.9.2.
What types of attacks can CVE-2024-32557 facilitate?
CVE-2024-32557 can facilitate stored XSS attacks, allowing an attacker to inject malicious scripts into web pages retrieved by users.
Which versions of Exclusive Addons Elementor are affected by CVE-2024-32557?
Exclusive Addons Elementor versions up to and including 2.6.9.2 are affected by CVE-2024-32557.
Is user input vulnerable in CVE-2024-32557?
Yes, CVE-2024-32557 involves improper neutralization of user input during web page generation.