CVE-2024-5553: Premium Addons for Elementor <= 4.10.33 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, 4.10.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses and edits an injected element, and subsequently clicks the element with the mouse scroll wheel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5553?
CVE-2024-5553 has a high severity due to the potential for DOM-Based Stored Cross-Site Scripting, which can lead to significant security risks if exploited.
How do I fix CVE-2024-5553?
To fix CVE-2024-5553, update the Premium Addons for Elementor plugin to version 4.10.34 or later, which addresses the identified vulnerabilities.
Who is affected by CVE-2024-5553?
CVE-2024-5553 affects users of the Premium Addons for Elementor plugin for WordPress up to and including version 4.10.33.
What kind of attacks can CVE-2024-5553 facilitate?
CVE-2024-5553 can facilitate authenticated attacker exploits that may lead to arbitrary script execution in a user's browser session.
What are the potential impacts of CVE-2024-5553 if exploited?
If exploited, CVE-2024-5553 could result in unauthorized access to user data, session hijacking, and the injection of malicious payloads.