CVE-2024-31236
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Apr 7, 2024
Updated: Jan 8, 2025
CWE ID 79
Summary
CVE-2024-31236 is a Cross-Site Scripting (XSS) vulnerability affecting WP Royal's Royal Elementor Addons. The flaw, classified as an Improper Neutralization of Input vulnerability, allows an attacker to inject malicious scripts during web page generation. This stored XSS issue can be exploited to execute malicious code on a victim's browser when they view a specially crafted webpage. Affected versions of Royal Elementor Addons range from n/a through 1.3.93. Users are advised to update to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share