CVE-2024-4452: ElementsKit Pro <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/elementskit-proto a version that resolves this vulnerability.Fixed in 3.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4452?
CVE-2024-4452 is classified as a vulnerability that allows for Stored Cross-Site Scripting which can significantly impact site security.
How do I fix CVE-2024-4452?
To fix CVE-2024-4452, update the ElementsKit Pro plugin to version 3.6.2 or later to ensure input sanitization and output escaping are properly implemented.
Who is affected by CVE-2024-4452?
Authenticated users with contributor-level access can exploit CVE-2024-4452 if using ElementsKit Pro versions up to 3.6.1.
What are the conditions of CVE-2024-4452 exploitation?
CVE-2024-4452 can be exploited through the ‘url’ parameter due to insufficient sanitization and output escaping in the affected plugin versions.
Is there a workaround for CVE-2024-4452 if I can't update immediately?
As a temporary workaround for CVE-2024-4452, consider disabling the ElementsKit Pro plugin until the update can be applied.