CVE-2024-10325
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-10325 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Elementor Header & Footer Builder plugin for WordPress. This issue, present in all versions up to and including 1.6.45, allows authenticated attackers with Author-level access or higher to inject malicious scripts via SVG file uploads through the plugin's REST API. The insufficient input sanitization and output escaping in the plugin make it possible for attackers to execute arbitrary web scripts on pages every time a user accesses the affected SVG file. This poses a significant security risk and requires immediate patching to protect WordPress websites using the Elementor plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Brainstorm Force