CVE-2024-5787
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jun 13, 2024
Updated: Jul 2, 2024
CWE ID 79
Summary
CVE-2024-5787 is a stored cross-site scripting (XSS) vulnerability affecting the PowerPack Addons for Elementor plugin for WordPress. The flaw, present in all versions up to 2.7.20, can be exploited by authenticated attackers with Contributor-level access or higher. The vulnerability lies in the 'url' attribute of the plugin's Link Effects widget, which lacks proper input sanitization and output escaping. As a result, attackers can inject arbitrary web scripts, which will execute whenever a user accesses an injected page, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.