First published: Tue Apr 16 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Exclusive Addons for Elementor | <=2.6.9.2 | |
WordPress Exclusive Addons for Elementor | <=2.6.9.2 | |
<=2.6.9.2 |
Update to 2.6.9.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32557 is classified as a high severity vulnerability due to its potential for enabling stored cross-site scripting (XSS) attacks.
To fix CVE-2024-32557, update Exclusive Addons Elementor to the latest version that is beyond 2.6.9.2.
CVE-2024-32557 can facilitate stored XSS attacks, allowing an attacker to inject malicious scripts into web pages retrieved by users.
Exclusive Addons Elementor versions up to and including 2.6.9.2 are affected by CVE-2024-32557.
Yes, CVE-2024-32557 involves improper neutralization of user input during web page generation.