CVE-2024-9444: ElementsReady Addons for Elementor <= 6.4.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9444?
CVE-2024-9444 is considered a critical vulnerability due to the potential for authenticated attackers to execute stored cross-site scripting attacks.
How do I fix CVE-2024-9444?
To fix CVE-2024-9444, update the ElementsReady Addons for Elementor plugin to the latest version beyond 6.4.3 that addresses the vulnerability.
Who is affected by CVE-2024-9444?
All versions of the ElementsReady Addons for Elementor plugin for WordPress up to and including 6.4.3 are affected by CVE-2024-9444.
What type of attack can be executed using CVE-2024-9444?
CVE-2024-9444 allows authenticated attackers to perform stored cross-site scripting attacks via SVG file uploads.
What are the implications of CVE-2024-9444 for website security?
The implications of CVE-2024-9444 include potential malicious scripts being executed on users' browsers, leading to data theft or session hijacking.