CVE-2024-37922: WordPress Premium Addons for Elementor plugin <= 4.10.34 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.34.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37922?
CVE-2024-37922 is considered a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-37922?
To fix CVE-2024-37922, update the Premium Addons for Elementor to version 4.10.35 or later.
What impact does CVE-2024-37922 have on web applications?
CVE-2024-37922 can allow attackers to inject malicious scripts into web pages viewed by users, compromising user data and session integrity.
Which versions of Premium Addons for Elementor are affected by CVE-2024-37922?
CVE-2024-37922 affects Premium Addons for Elementor versions from n/a to 4.10.34.
Can CVE-2024-37922 be exploited remotely?
Yes, CVE-2024-37922 can be remotely exploited by attackers to execute scripts in the context of the affected web application.