PT-2024-16177 · Elementor · Element Pack Elementor Addons

·

CVE-2024-10310

·

Published

2024-11-01

·

Updated

2024-11-04

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Element Pack Elementor Addons versions up to, and including, 5.10.1
Description The vulnerability is a Stored Cross-Site Scripting issue due to insufficient input sanitization and output escaping in the Custom Gallery Widget image title parameter. This allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Recommendations For versions up to, and including, 5.10.1, update the plugin to the latest patched version immediately to mitigate risks. As a temporary workaround, consider restricting access to the Custom Gallery Widget until a patch is available. Avoid using the image title parameter in the affected widget until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10310

Affected Products

Element Pack Elementor Addons