CVE-2024-50555: WordPress Elementor Website Builder plugin <= 3.29.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows Stored XSS.This issue affects Elementor Website Builder: from n/a through <= 3.29.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50555?
CVE-2024-50555 is classified as a high-severity vulnerability due to its potential for Stored Cross Site Scripting (XSS).
How do I fix CVE-2024-50555?
To fix CVE-2024-50555, update the Elementor Website Builder plugin to a version later than 3.29.0 immediately.
What affects CVE-2024-50555?
CVE-2024-50555 affects versions of the Elementor Website Builder plugin up to and including 3.29.0 used in WordPress sites.
What is the impact of CVE-2024-50555 on a website?
The impact of CVE-2024-50555 may allow attackers to execute arbitrary JavaScript code in the context of a user's browser, potentially leading to data theft and unauthorized actions.
Can CVE-2024-50555 be exploited remotely?
Yes, CVE-2024-50555 can be exploited remotely, enabling attackers to inject malicious scripts into the website.