First published: Mon Jun 24 2024(Updated: )
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0; Masterstudy Elementor Widgets: from n/a through 1.2.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Consulting Elementor Widgets Wordpress | <1.3.1 |
Update Consulting Elementor Widgets to 1.3.1 or a higher version.
Update Masterstudy Elementor Widgets to 1.2.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37091 has a high severity level due to the potential for OS Command Injection.
To mitigate CVE-2024-37091, update the Consulting Elementor Widgets plugin to version 1.3.2 or later.
CVE-2024-37091 affects versions of the Consulting Elementor Widgets plugin prior to 1.3.2.
CVE-2024-37091 allows attackers to execute arbitrary commands on the server through command injection.
Users of the Consulting Elementor Widgets plugin for WordPress versions up to 1.3.1 are impacted by CVE-2024-37091.