CVE-2024-47392

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 5, 2024
Updated: Jan 22, 2025
CWE ID 79

Summary

CVE-2024-47392 is a newly disclosed Cross-site Scripting (XSS) vulnerability affecting BdThemes Element Pack Elementor Addons. The flaw, which permits Stored XSS attacks, exists due to improper neutralization of user input during web page generation. This vulnerability has been detected in all versions of the add-ons, from the earliest release through 5.7.5. Successful exploitation of this weakness could lead to the injection of malicious scripts into a user's web browser, potentially resulting in unauthorized access to sensitive information or the installation of malware. Users are strongly advised to update their BdThemes Element Pack Elementor Addons to the latest, secure version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share