CVE-2024-8482

NVD Published Date: October 08, 2024 at 12:15 PM
NVD Last Modified: October 10, 2024 at 12:56 PM
Download Patch
Vulnerability ID
CVE-2024-8482
Severity
MEDIUM
Severity Score
6.4
Summary
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Mitigation and Patches
-
Exploits
-
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CWE ID
CWE-79

Recent Publish

KB5042749

KB5042881

CVE-2024-33073

CVE-2024-23370

KB5043049

KB5043050

See More ...

See SecOps Solution
in action

Schedule Demo