First published: Thu Jan 02 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moveaddons Move Addons for Elementor | <1.3.7 | |
Move Addons for Elementor | <=1.3.6 | |
WordPress Move Addons for Elementor | <=1.3.6 |
Update the WordPress Move Addons for Elementor plugin to the latest available version (at least 1.3.7).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56254 is classified as a Stored Cross-site Scripting (XSS) vulnerability, which can potentially allow attackers to execute scripts in the context of a user's browser.
To fix CVE-2024-56254, update Move Addons for Elementor to the latest version beyond 1.3.6.
CVE-2024-56254 affects Move Addons for Elementor versions from n/a up to and including 1.3.6.
Stored XSS in CVE-2024-56254 refers to an attack where malicious scripts are stored on the server and then executed in the browser of users who access the affected page.
Users and administrators using versions of Move Addons for Elementor up to 1.3.6 on their WordPress sites are impacted by CVE-2024-56254.