CVE-2024-52471: WordPress Extensions for Elementor plugin <= 2.0.40 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor extensions-for-elementor allows Reflection Injection.This issue affects Extensions for Elementor: from n/a through <= 2.0.40.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52471?
CVE-2024-52471 is classified as a critical vulnerability due to the potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2024-52471?
To fix CVE-2024-52471, upgrade the Extensions for Elementor plugin to version 2.0.38 or later.
What is the impact of CVE-2024-52471?
The impact of CVE-2024-52471 includes the possibility of attackers executing scripts in the context of another user, leading to data theft or unauthorized actions.
Who is affected by CVE-2024-52471?
CVE-2024-52471 affects all versions of Extensions for Elementor up to and including 2.0.37.
Is there a workaround for CVE-2024-52471?
There is no known workaround for CVE-2024-52471; updating the plugin is the only effective mitigation.