CVE-2024-13113

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Feb 26, 2025

Summary

CVE-2024-13113 is a vulnerability affecting the Countdown Timer plugin for Elementor in WordPress. Before version 1.3.7, the plugin fails to sanitize and escape certain parameters when rendering them on webpages. This flaw allows contributors, with a relatively low level of access, to execute Cross-Site Scripting (XSS) attacks on unsuspecting users, potentially leading to data theft or unauthorized website manipulation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share