CVE-2024-52356: WordPress The Pack Elementor addons plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack Elementor addons the-pack-addon allows Stored XSS.This issue affects The Pack Elementor addons: from n/a through <= 2.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52356?
CVE-2024-52356 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-52356?
To fix CVE-2024-52356, update the Webangon The Pack Elementor addons plugin to version 2.1.1 or later.
What software is affected by CVE-2024-52356?
CVE-2024-52356 affects Webangon The Pack Elementor addons versions prior to 2.1.1.
What are the potential impacts of CVE-2024-52356?
Exploitation of CVE-2024-52356 can lead to unauthorized access to user data and account compromise due to stored XSS.
Is there a workaround for CVE-2024-52356 if I cannot update?
Currently, there is no known workaround for CVE-2024-52356, so updating the plugin is strongly recommended.