CVE-2024-12597
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-12597 is a stored Cross-Site Scripting (XSS) vulnerability affecting the HT Mega – Absolute Addons For Elementor plugin for WordPress. This issue, present in all versions up to and including 2.7.6, allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into pages through the 'block_css' and 'inner_css' parameters. The insufficient input sanitization and output escaping in these parameters enable the attacker's code to be stored and executed whenever a user accesses the injected page. This vulnerability poses a serious security risk, as it can lead to unintended functionality, data theft, or unauthorized access to a WordPress site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.