CVE-2024-1171
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Feb 29, 2024
Updated: Jan 8, 2025
CWE ID 862
Summary
CVE-2024-1171 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Essential Addons for Elementor plugin for WordPress. This issue, present in versions up to 5.9.8, stems from insufficient input sanitization and output escaping in the Filterable Gallery Widget. Authenticated attackers with contributor-level access or higher can exploit this vulnerability to inject arbitrary web scripts. Upon accessing an injected page, these scripts will execute, posing a significant threat to website security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- WP Job Portal Plugin
Affected Vendors
- WordPress