CVE-2024-49259: WordPress Primary Addon for Elementor plugin <= 1.5.8 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Primary Addon for Elementor primary-addon-for-elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through <= 1.5.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49259?
CVE-2024-49259 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-49259?
To mitigate CVE-2024-49259, update the NicheAddons Primary Addon for Elementor to version 1.5.9 or later.
What types of requests are affected by CVE-2024-49259?
CVE-2024-49259 affects any web page generation requests that utilize user input without proper sanitization.
Who is affected by CVE-2024-49259?
Any users of the NicheAddons Primary Addon for Elementor up to version 1.5.8 are vulnerable to CVE-2024-49259.
What is the nature of CVE-2024-49259?
CVE-2024-49259 involves improper neutralization of user input, leading to Stored XSS vulnerabilities on affected sites.