CVE-2024-50442: WordPress Royal Elementor Addons and Templates plugin <= 1.3.980 - XML External Entity (XXE) vulnerability
Published Oct 28, 2024
·Updated
Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through <= 1.3.980.
Affected Software
1 affected component
royal-elementor-addons Royal Elementor Addons Wordpress<1.3.981
Remediation
Information
Update to 1.3.981 or a higher version.
Event History
Oct 28, 2024
CVE Published
via MITRE·11:14 AM
Data Sourced
via MITRE·11:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-50442?
CVE-2024-50442 is considered a high severity vulnerability due to its potential for XML Injection.
2
How do I fix CVE-2024-50442?
To fix CVE-2024-50442, update the Royal Elementor Addons plugin to version 1.3.981 or later.
3
What software is affected by CVE-2024-50442?
CVE-2024-50442 affects the Royal Elementor Addons plugin version 1.3.980 and earlier.
4
What type of vulnerability is CVE-2024-50442?
CVE-2024-50442 is an Improper Restriction of XML External Entity Reference vulnerability.
5
Can CVE-2024-50442 lead to data breaches?
Yes, CVE-2024-50442 can potentially be exploited to extract sensitive information, leading to data breaches.