CVE-2024-45454
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Oct 6, 2024
Updated: Feb 5, 2025
CWE ID 79
Summary
CVE-2024-45454 is a Cross-site Scripting (XSS) vulnerability affecting Unlimited Elements Unlimited Elements For Elementor, a plugin used for creating widgets, add-ons, and templates with Elementor. The issue enables attackers to inject malicious scripts into web pages generated by the plugin, version 1.5.121 and below, through improper neutralization of user input. Successful exploitation of this vulnerability could lead to unauthorized access, data theft, or site defacement, making it essential for users to apply the necessary security patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.