CVE-2024-47366
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Oct 6, 2024
Updated: Jan 29, 2025
CWE ID 79
Summary
CVE-2024-47366 is a newly disclosed Cross-site Scripting (XSS) vulnerability affecting WPVibes Elementor Addon Elements. The issue arises due to improper neutralization of user inputs during the generation of web pages. An attacker can exploit this flaw to inject malicious scripts into a victim's webpage, potentially gaining unauthorized access or stealing sensitive information. Impacted versions of Elementor Addon Elements range from n/a to 1.13.6. It is crucial for users to apply the necessary updates or patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.