CVE-2024-1234
MEDIUMExclusiveaddons Exclusive Addons For Elementor < 2.6.9.1 - XSS
Title source: ruleDescription
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploits (1)
exploitdb
WORKING POC
by Al Baradi Joy · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52126
Scores
CVSS v3
6.4
EPSS
0.1059
EPSS Percentile
93.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
exclusiveaddons/exclusive_addons_for_elementor
< 2.6.9.1
timstrifler/Exclusive Addons for Elementor
< 2.6.9
Published
Mar 13, 2024
Tracked Since
Feb 18, 2026