vendor:
                    Exclusive Addons for Elementor
                by:
                    Al Baradi Joy
                5.1
                        CVSS
                    MEDIUM
                    Stored Cross-Site Scripting (XSS)
                    79
                        CWE
                    Product Name: Exclusive Addons for Elementor
                    Affected Version From:  Up to and including 2.6.9
                    Affected Version To:  39966
                    Patch Exists: YES
                    Related CWE: CVE-2024-1234
                    CPE:  a:exclusiveaddons:exclusive_addons_for_elementor:2.6.9
                    Platforms Tested:  WordPress
                    2024
                    Exclusive Addons for Elementor ≤ 2.6.9 – Authenticated Stored Cross-Site Scripting (XSS)
The Exclusive Addons for Exclusive Addons for Elementor for WordPress, in versions up to and including 2.6.9, is vulnerable to stored cross-site scripting (XSS) via the 's' parameter. Improper input sanitization and output escaping allow an attacker with contributor-level permissions or higher to inject arbitrary JavaScript that executes when a user views the affected page.
Mitigation:
					Ensure proper input validation and output escaping to prevent XSS attacks. Update to version 2.7.0 or higher.