CVE-2024-29792
WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability
Record summary
CVE-2024-29792 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.93.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 25, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)Browse Unlimited Elements / Unlimited Elements For Elementor (Free Widgets, Addons, Templates)unlimited-elements-for-elementorDefault status: unaffected | CVE List | Through 1.5.93 | affected |
unlimited_elements_for_elementorBrowse unlimited-elements / unlimited_elements_for_elementor | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMUnlimited Elements for Elementor <= 1.5.93 - Cross Site ScriptingCVSS 6.1
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions up to 1.5.93 contain a reflected cross-site scripting caused by improper neutralization of input during web page generation, letting attackers execute malicious scripts in the victim's browser, exploit requires attacker to craft a malicious URL.
Impact
Attackers can execute arbitrary scripts in the victim's browser, potentially leading to session hijacking, defacement, or redirection.
Remediation
Update to version 1.5.94 or later.
Source: ProjectDiscovery