CVE-2024-4489: Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customuploadmimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4489?
CVE-2024-4489 has a moderate severity level due to the potential for stored cross-site scripting vulnerabilities.
How do I fix CVE-2024-4489?
To fix CVE-2024-4489, update the Royal Elementor Addons and Templates plugin to version 1.3.977 or higher.
What versions are affected by CVE-2024-4489?
CVE-2024-4489 affects versions of the Royal Elementor Addons plugin up to and including 1.3.976.
What impact does CVE-2024-4489 have on my website?
CVE-2024-4489 can allow an attacker to execute malicious scripts on the website, potentially compromising user data.
Is user authentication required to exploit CVE-2024-4489?
No, CVE-2024-4489 can be exploited by authenticated users, making it particularly concerning for sites with user-generated content.