CVE-2024-12851

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 8, 2025
Updated: Jan 17, 2025
CWE ID 79

Summary

CVE-2024-12851 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Elementor Addons plugin for WordPress. The vulnerability lies in the Cookie Consent Widget's custom_attributes parameter, which lacks adequate input sanitization and output escaping. This weakness allows authenticated attackers with Contributor-level access and above to inject malicious scripts. Successful exploitation results in the execution of arbitrary web code whenever a user accesses an injected page. Versions of the plugin up to, and including, 5.10.14 are vulnerable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share