First published: Mon Jun 03 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.15.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Essential Addons for Elementor | <=5.9.15 | |
WordPress Essential Addons for Elementor | <=5.9.15 | |
WPDeveloper Essential Addons for Elementor | <5.9.16 |
Update to 5.9.16 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34764 is classified as a high severity vulnerability due to its potential for Stored Cross-site Scripting (XSS).
To fix CVE-2024-34764, update the Essential Addons for Elementor plugin to the latest version beyond 5.9.15.
CVE-2024-34764 can facilitate Stored Cross-site Scripting attacks, allowing attackers to execute malicious scripts in the context of users' browsers.
CVE-2024-34764 affects all versions of the Essential Addons for Elementor plugin from an unspecified version up to and including 5.9.15.
Users of the Essential Addons for Elementor plugin on WordPress who have not upgraded beyond version 5.9.15 are affected by CVE-2024-34764.