First published: Sun Dec 01 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs Countdown Timer for Elementor allows Stored XSS.This issue affects Countdown Timer for Elementor: from n/a through 1.3.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Countdown Timer for Elementor | <=1.3.6 | |
WordPress Countdown Timer for Elementor | <=1.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53743 is a high severity vulnerability due to its potential for Stored Cross-site Scripting (XSS).
To fix CVE-2024-53743, upgrade FlickDevs Countdown Timer for Elementor to version 1.3.7 or higher.
The impact of CVE-2024-53743 allows attackers to execute arbitrary JavaScript code in the context of a user's browser.
CVE-2024-53743 affects FlickDevs Countdown Timer for Elementor from versions n/a through 1.3.6.
There is currently no public exploit reported for CVE-2024-53743, but it remains a significant risk for users of the affected plugin.