First published: Sun Aug 18 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder allows Stored XSS.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: from n/a through 2.4.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hasthemes Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks | <=2.4.1 | |
VoidCoders Void Contact Form 7 Widget for Elementor Page Builder | <=2.4.1 | |
<2.4.2 |
Update to 2.4.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43291 is classified as a high-severity vulnerability due to its potential for stored XSS attacks.
To fix CVE-2024-43291, update the Void Contact Form 7 Widget For Elementor Page Builder to version 2.4.2 or later.
CVE-2024-43291 is a Cross-site Scripting (XSS) vulnerability that allows for the improper neutralization of input.
CVE-2024-43291 affects all versions of the Void Contact Form 7 Widget For Elementor Page Builder up to and including version 2.4.1.
The vendor for CVE-2024-43291 is voidCoders, which develops the Void Contact Form 7 Widget For Elementor Page Builder.