CVE-2024-1377
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-1377 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Happy Addons for Elementor plugin for WordPress. This issue, present in all versions up to 3.10.3, allows authenticated attackers with contributor-level access or higher to inject malicious scripts into the 'author_meta_tag' attribute of the Author Meta widget. Successful exploitation results in the execution of these scripts whenever a user accesses an injected page. This vulnerability poses a significant security risk, as it can lead to unintended website behavior, data theft, and potential account takeover. It is essential for users to update the plugin to the latest version to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.