CVE-2024-51585: WordPress Sales Page Addon plugin <= 1.4.5 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Sales Page Addon – Elementor & Beaver Builder sales-page-addon allows Stored XSS.This issue affects Sales Page Addon – Elementor & Beaver Builder: from n/a through <= 1.4.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51585?
CVE-2024-51585 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2024-51585?
To fix CVE-2024-51585, update the NicheAddons Sales Page Addon – Elementor & Beaver Builder to a version higher than 1.4.2.
What impact does CVE-2024-51585 have on my website?
CVE-2024-51585 can allow an attacker to execute malicious scripts in the context of the user's browser, compromising user data.
Is CVE-2024-51585 easy to exploit?
Yes, CVE-2024-51585 is relatively easy to exploit if the attacker targets vulnerable versions of the NicheAddons Sales Page Addon.
Which versions are affected by CVE-2024-51585?
CVE-2024-51585 affects all versions of the NicheAddons Sales Page Addon – Elementor & Beaver Builder up to and including 1.4.2.