First published: Wed Oct 30 2024(Updated: )
The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Modernaweb Black Widgets For Elementor | <1.3.8 | |
Black Widgets | <=1.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9388 has a high severity rating due to its potential for stored cross-site scripting attacks.
To fix CVE-2024-9388, update the Black Widgets For Elementor plugin to the latest version above 1.3.7.
CVE-2024-9388 affects users of the Black Widgets For Elementor plugin for WordPress versions up to and including 1.3.7.
CVE-2024-9388 is a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts.
An attacker exploiting CVE-2024-9388 can execute unauthorized scripts in the context of other users, potentially compromising sensitive information.