vendor:
Exclusive Addons for Elementor
by:
Al Baradi Joy
5.1
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Exclusive Addons for Elementor
Affected Version From: Up to and including 2.6.9
Affected Version To: 39966
Patch Exists: YES
Related CWE: CVE-2024-1234
CPE: a:exclusiveaddons:exclusive_addons_for_elementor:2.6.9
Platforms Tested: WordPress
2024
Exclusive Addons for Elementor ≤ 2.6.9 – Authenticated Stored Cross-Site Scripting (XSS)
The Exclusive Addons for Exclusive Addons for Elementor for WordPress, in versions up to and including 2.6.9, is vulnerable to stored cross-site scripting (XSS) via the 's' parameter. Improper input sanitization and output escaping allow an attacker with contributor-level permissions or higher to inject arbitrary JavaScript that executes when a user views the affected page.
Mitigation:
Ensure proper input validation and output escaping to prevent XSS attacks. Update to version 2.7.0 or higher.