First published: Thu May 09 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Thim Elementor Kit allows Stored XSS.This issue affects Thim Elementor Kit: from n/a through 1.1.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ThimPress Thim Elementor Kit | >=1.1.8 | |
WordPress Thim Elementor Kit | <=1.1.8 |
Update to 1.1.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34415 is classified as a Stored XSS vulnerability, which can lead to unauthorized access and data theft.
To resolve CVE-2024-34415, update Thim Elementor Kit to the latest version that addresses this vulnerability.
CVE-2024-34415 affects Thim Elementor Kit versions from n/a through 1.1.8.
CVE-2024-34415 allows for Cross-site Scripting (XSS) attacks, enabling attackers to inject malicious scripts into web pages.
Yes, CVE-2024-34415 can be exploited with relative ease, especially if proper input sanitization is not enforced.