First published: Mon May 06 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.4.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
POSIMYTH The Plus Addons for Elementor Page Builder Lite | <=5.4.2 | |
WordPress The Plus Addons for Elementor Pro | <=5.4.2 | |
posimyth The Plus Addons for Elementor WordPress | <5.5.0 |
Update to 5.5.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34373 is categorized as a Stored Cross-site Scripting (XSS) vulnerability, which can have high impact on security.
To fix CVE-2024-34373, update The Plus Addons for Elementor Page Builder Lite to version 5.4.3 or later.
CVE-2024-34373 affects The Plus Addons for Elementor Page Builder Lite versions up to and including 5.4.2.
CVE-2024-34373 is a Cross-site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
You can identify CVE-2024-34373 by checking for The Plus Addons for Elementor Page Builder Lite version 5.4.2 or earlier installed on your WordPress site.