CVE-2024-8482
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-8482 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Royal Elementor Addons and Templates plugin for WordPress. Versions up to and including 1.3.982 are vulnerable, exposing pages to injection of arbitrary web scripts. Attackers with Contributor-level access or higher can exploit this issue by manipulating the ‘url’ parameter, leading to the execution of malicious code whenever a user accesses an injected page. This input sanitization and output escaping failure poses a significant security risk to WordPress sites using the Royal Elementor Addons and Templates plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.