CVE-2024-56062: WordPress Royal Elementor Addons and Templates plugin <= 1.3.987 - Cross Site Scripting (XSS) vulnerability
Published Dec 31, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.3.987.
Affected Software
3 affected components
royal-elementor-addons Royal Elementor Addons Wordpress<=1.3.987
WP Royal Royal Elementor Addons<=1.3.987
WordPress Royal Elementor Addons and Templates<=1.3.987
Remediation
Information
Update the WordPress Royal Elementor Addons plugin to the latest available version (at least 1.7.1).
Event History
Dec 31, 2024
CVE Published
via MITRE·11:07 PM
Data Sourced
via MITRE·11:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56062?
CVE-2024-56062 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-56062?
To fix CVE-2024-56062, update the Royal Elementor Addons to the latest version beyond 1.3.987.
3
What versions of Royal Elementor Addons are affected by CVE-2024-56062?
CVE-2024-56062 affects Royal Elementor Addons versions up to and including 1.3.987.
4
What is the impact of CVE-2024-56062?
If exploited, CVE-2024-56062 can allow attackers to execute malicious scripts in the context of a user's session.
5
Does CVE-2024-56062 affect other WordPress plugins?
CVE-2024-56062 specifically affects the Royal Elementor Addons and does not impact other WordPress plugins directly.