First published: Mon Nov 11 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cool Plugins Web Stories Widgets For Elementor allows Stored XSS.This issue affects Web Stories Widgets For Elementor: from n/a through 1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Coolplugins Web Stories Widgets | <1.1.1 |
Update to 1.1.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52354 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
To mitigate CVE-2024-52354, upgrade the Web Stories Widgets For Elementor plugin to version 1.1.1 or higher.
CVE-2024-52354 is an improper neutralization of input vulnerability leading to stored cross-site scripting (XSS).
CVE-2024-52354 affects all versions of Web Stories Widgets For Elementor up to but not including version 1.1.1.
Any user of the Cool Plugins Web Stories Widgets For Elementor plugin in WordPress versions prior to 1.1.1 is at risk of CVE-2024-52354.