Record summary

CVE-2024-29792 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.93.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 25, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Browse Unlimited Elements / Unlimited Elements For Elementor (Free Widgets, Addons, Templates)unlimited-elements-for-elementor

Default status: unaffected

CVE ListThrough 1.5.93affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMUnlimited Elements for Elementor <= 1.5.93 - Cross Site ScriptingCVSS 6.1

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions up to 1.5.93 contain a reflected cross-site scripting caused by improper neutralization of input during web page generation, letting attackers execute malicious scripts in the victim's browser, exploit requires attacker to craft a malicious URL.

Impact

Attackers can execute arbitrary scripts in the victim's browser, potentially leading to session hijacking, defacement, or redirection.

Remediation

Update to version 1.5.94 or later.

WeaknessesCWE-79
AuthorsShivam Kamboj
Template tagscvecve2024wordpresswpwp-pluginxssunlimited-elements-for-elementorauthenticatedvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

3