CVE-2024-8482

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Jan 15, 2025
CWE ID 79

Summary

CVE-2024-8482 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Royal Elementor Addons and Templates plugin for WordPress. Versions up to and including 1.3.982 are vulnerable, exposing pages to injection of arbitrary web scripts. Attackers with Contributor-level access or higher can exploit this issue by manipulating the ‘url’ parameter, leading to the execution of malicious code whenever a user accesses an injected page. This input sanitization and output escaping failure poses a significant security risk to WordPress sites using the Royal Elementor Addons and Templates plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share