First published: Wed Oct 16 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in nayon46 Unlimited Addon For Elementor allows Stored XSS.This issue affects Unlimited Addon For Elementor: from n/a through 2.0.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nayon46 Unlimited Addon For Elementor | <=2.0.0 | |
WordPress Unlimited Addon For Elementor | <=2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49267 is classified as a high severity vulnerability due to its potential for exploitation via stored cross-site scripting (XSS).
CVE-2024-49267 allows attackers to inject malicious scripts that can be executed in the context of the user's browser, affecting all users who interact with the compromised element on the site.
To fix CVE-2024-49267, update the Unlimited Addon For Elementor plugin to a version greater than 2.0.0 which addresses this vulnerability.
Symptoms of exploitation of CVE-2024-49267 may include unexpected pop-ups, unauthorized actions being performed on behalf of the user, or redirection to malicious websites.
Yes, CVE-2024-49267 affects all versions of Unlimited Addon For Elementor up to and including version 2.0.0.