CVE-2024-49264: WordPress Events Addon for Elementor plugin <= 2.2.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Events Addon for Elementor events-addon-for-elementor allows Stored XSS.This issue affects Events Addon for Elementor: from n/a through <= 2.2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49264?
The severity of CVE-2024-49264 is considered high due to the potential for stored cross-site scripting (XSS).
How do I fix CVE-2024-49264?
To fix CVE-2024-49264, upgrade the NicheAddons Events Addon for Elementor to a version higher than 2.2.0.
What type of vulnerability is CVE-2024-49264?
CVE-2024-49264 is an improper neutralization of input during web page generation, leading to stored Cross-site Scripting (XSS).
Which versions are affected by CVE-2024-49264?
CVE-2024-49264 affects all versions of NicheAddons Events Addon for Elementor up to and including version 2.2.0.
What is the impact of CVE-2024-49264?
The impact of CVE-2024-49264 allows an attacker to inject malicious scripts into web pages, compromising user data and security.