CVE-2024-51629

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 79

Summary

CVE-2024-51629 is a Cross-site Scripting (XSS) vulnerability affecting the MetricThemes Header Footer Composer for Elementor plugin. The flaw, which permits DOM-Based XSS, is located in the plugin's web page generation process. By injecting malicious scripts into the affected plugin, an attacker can manipulate a user's web session and potentially steal sensitive data or take control of the user's account. This vulnerability impacts versions of the Header Footer Composer for Elementor plugin from n/a through 1.0.4. Users are strongly advised to update to the latest, secure version of the plugin as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share