CVE-2024-47626
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-47626 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting RomethemeKit For Elementor from an unknown version up to 1.5.0. Hackers can exploit this Improper Neutralization of Input During Web Page Generation flaw to inject malicious scripts into a website, potentially stealing user data or taking control of the site. The vulnerability may lead to Stored XSS attacks, allowing attackers to execute scripts even after the initial exploit has been remedied. Website owners using RomethemeKit For Elementor are urged to update to the latest version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.