First published: Sun Oct 06 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Unlimited Elements For Elementor | <1.5.122 | |
Unlimited Elements for Elementor | <1.5.121 | |
WordPress Unlimited Elements For Elementor | <1.5.121 |
Update to 1.5.122 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45454 is classified as a high-severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2024-45454, update the Unlimited Elements for Elementor plugin to the latest version available beyond 1.5.121.
CVE-2024-45454 allows attackers to perform reflected XSS attacks, potentially compromising user sessions or injecting malicious scripts.
CVE-2024-45454 affects Unlimited Elements for Elementor up to version 1.5.121.
Yes, user data can be at risk because attackers exploit CVE-2024-45454 to execute scripts in the context of the user's browser.