CVE-2024-32785: WordPress The Pack Elementor addons plugin <= 2.0.8.3 - Cross Site Request Forgery (CSRF) to XSS vulnerability
Published Apr 24, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Webangon The Pack Elementor addons allows Cross-Site Scripting (XSS).This issue affects The Pack Elementor addons: from n/a through 2.0.8.3.
Affected Software
3 affected components
webangon The Pack Elementor Addons Wordpress<2.0.8.4
webangon The Pack Elementor addons<=2.0.8.3
WordPress The Pack Elementor addons<=2.0.8.3
Remediation
Information
Update to 2.0.8.4 or a higher version.
Event History
Apr 24, 2024
CVE Published
via MITRE·10:22 AM
Data Sourced
via MITRE·10:22 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32785?
CVE-2024-32785 is classified as a high severity vulnerability due to its potential for Cross-Site Request Forgery leading to Cross-Site Scripting.
2
How do I fix CVE-2024-32785?
To address CVE-2024-32785, update the Webangon The Pack Elementor addons to version 2.0.8.4 or higher.
3
Which versions of The Pack Elementor addons are affected by CVE-2024-32785?
CVE-2024-32785 affects The Pack Elementor addons version 2.0.8.3 and earlier.
4
What type of attack can CVE-2024-32785 facilitate?
CVE-2024-32785 can facilitate Cross-Site Scripting (XSS) attacks through Cross-Site Request Forgery.
5
Where can I find more information about CVE-2024-32785?
Detailed information regarding CVE-2024-32785 can be found in vulnerability databases and security advisories.