CVE-2024-4865: Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4865?
CVE-2024-4865 has been classified as a medium severity vulnerability due to its potential to allow stored cross-site scripting attacks.
How do I fix CVE-2024-4865?
To fix CVE-2024-4865, upgrade the Happy Addons for Elementor plugin to version 3.10.9 or higher, which includes the necessary security patches.
Who is affected by CVE-2024-4865?
All versions of the Happy Addons for Elementor plugin for WordPress up to and including 3.10.8 are affected by CVE-2024-4865.
What type of vulnerability is CVE-2024-4865?
CVE-2024-4865 is a stored cross-site scripting (XSS) vulnerability, which can be exploited by authenticated attackers.
Can CVE-2024-4865 be exploited remotely?
CVE-2024-4865 can be exploited by authenticated users, making it a significant threat to websites using the vulnerable plugin.