CVE-2024-52354
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Nov 11, 2024
Updated: Nov 15, 2024
CWE ID 79
Summary
CVE-2024-52354 is a newly disclosed Cross-site Scripting (XSS) vulnerability affecting the Cool Plugins Web Stories Widgets For Elementor. This issue permits attackers to inject malicious scripts into web pages generated by the widget, leading to Stored XSS attacks. The vulnerability exists in Web Stories Widgets For Elementor, with versions from n/a through 1.1 being affected. Users are encouraged to update to the latest patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.