CVE-2024-9673

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 8, 2025
CWE ID 79

Summary

CVE-2024-9673 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Piotnet Addons For Elementor plugin for WordPress. This issue, present in all versions up to 2.4.31, permits authenticated attackers with contributor-level access and above to inject malicious scripts into the plugin's Heading widget. The insufficient input sanitization and output escaping on user-supplied attributes allow the attacker to execute arbitrary web scripts whenever a user accesses an affected page. This vulnerability poses a significant risk to websites using the Piotnet Addons For Elementor plugin and can lead to various types of attacks. It is essential that users update to the latest version of the plugin to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Piotnet Addons for Elementor Plugin

Affected Vendors

  • WordPress