CVE-2024-5612: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox and Modal Widget
The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eaellightboxopenbtnicon’ parameter within the Lightbox & Modal widget in all versions up to, and including, 5.8.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Essential Addons for Elementor Proto a version that resolves this vulnerability.Fixed in 5.8.15 - Compensating control
Limit or remove Contributor+ (authenticated Contributor and above) capabilities for users who can edit pages to prevent authenticated stored XSS injection via the Lightbox & Modal widget.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5612?
CVE-2024-5612 is classified as a medium severity vulnerability.
How do I fix CVE-2024-5612?
To remediate CVE-2024-5612, update the Essential Addons for Elementor Pro plugin to version 5.8.16 or later.
What type of vulnerability is CVE-2024-5612?
CVE-2024-5612 is a Stored Cross-Site Scripting (XSS) vulnerability.
What versions of the plugin are affected by CVE-2024-5612?
All versions of the Essential Addons for Elementor Pro plugin up to and including 5.8.15 are affected by CVE-2024-5612.
What is the impact of CVE-2024-5612?
CVE-2024-5612 allows attackers to inject malicious scripts, potentially compromising user data and session security.