CVE-2024-54314: WordPress Primary Addon for Elementor plugin <= 1.6.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Primary Addon for Elementor primary-addon-for-elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through <= 1.6.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54314?
CVE-2024-54314 is classified as a high severity vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2024-54314?
To fix CVE-2024-54314, update the NicheAddons Primary Addon for Elementor to version 1.6.1 or higher.
What does CVE-2024-54314 affect?
CVE-2024-54314 affects versions of the NicheAddons Primary Addon for Elementor from any version up to and including 1.6.0.
What is Stored XSS in the context of CVE-2024-54314?
Stored XSS in CVE-2024-54314 refers to the vulnerability that allows an attacker to inject malicious scripts that are stored on the server and executed in users' browsers.
Is CVE-2024-54314 being actively exploited?
As of now, there have been indications of active exploitation of CVE-2024-54314 in the wild.