CVE-2024-37541: WordPress Elementor Addons, Widgets and Enhancements – Stax plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StaxWP Elementor Addons, Widgets and Enhancements – Stax stax-addons-for-elementor allows DOM-Based XSS.This issue affects Elementor Addons, Widgets and Enhancements – Stax: from n/a through <= 1.5.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37541?
CVE-2024-37541 is classified as a high-severity vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2024-37541?
To mitigate CVE-2024-37541, update the Stax Elementor Addons, Widgets, and Enhancements to version 1.4.4.2 or later.
Which versions are affected by CVE-2024-37541?
CVE-2024-37541 affects all versions of Stax Elementor Addons, Widgets, and Enhancements up to and including version 1.4.4.1.
What type of vulnerability is CVE-2024-37541?
CVE-2024-37541 is an Improper Neutralization of Input During Web Page Generation vulnerability that leads to Cross-site Scripting (XSS).
What are the potential impacts of CVE-2024-37541?
The potential impacts of CVE-2024-37541 include unauthorized access to user information and the ability to execute malicious scripts in the context of user sessions.