First published: Thu Apr 18 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.1.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mega Elements | <=1.1.9 | |
WordPress Mega Elements | <=1.1.9 | |
Kraftplugins Mega Elements | <1.2.0 |
Update to 1.2.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32575 is a stored Cross-site Scripting (XSS) vulnerability that can allow attackers to execute scripts in the context of a user session.
To mitigate CVE-2024-32575, update Kraftplugins Mega Elements to a version above 1.1.9 or apply any available security patches.
CVE-2024-32575 affects all versions of Kraftplugins Mega Elements up to and including 1.1.9.
CVE-2024-32575 involves improper neutralization of input during web page generation, leading to stored XSS vulnerabilities.
Yes, WordPress users utilizing the Mega Elements plugin up to version 1.1.9 are vulnerable to CVE-2024-32575.