CVE-2024-34374: WordPress ElementsReady Addons for Elementor plugin <= 5.8.0 - Cross Site Scripting (XSS) vulnerability
Published May 6, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 5.8.0.
Affected Software
3 affected components
QuomodoSoft Elementsready Wordpress<5.8.1
QuomodoSoft ElementsReady Addons for Elementor<=5.8.0
WordPress ElementsReady Addons for Elementor<=5.8.0
Remediation
Information
Update to 5.9.0 or a higher version.
Event History
May 6, 2024
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34374?
CVE-2024-34374 has a high severity rating due to its potential for Stored XSS attacks.
2
How do I fix CVE-2024-34374?
To fix CVE-2024-34374, update the ElementsReady Addons for Elementor to version 5.8.1 or higher.
3
What type of vulnerability is CVE-2024-34374?
CVE-2024-34374 is classified as a Cross-site Scripting (XSS) vulnerability.
4
What versions of ElementsReady Addons for Elementor are affected by CVE-2024-34374?
CVE-2024-34374 affects all versions of ElementsReady Addons for Elementor from n/a through 5.8.0.
5
Can CVE-2024-34374 allow attackers to compromise a website?
Yes, CVE-2024-34374 can enable attackers to inject malicious scripts, potentially compromising a website.