Input validation vulnerability in The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce 5.4.2

The Plus Addons for Elementor plugin for WordPress is at risk for a type of attack called Stored Cross-Site Scripting. This is because the plugin does not properly clean up user input and output, allowing attackers to insert harmful scripts into the website. This can be done by someone with contributor access or higher, and the scripts will run whenever a user visits a page with the injected code. It is possible that another reported issue, CVE-2024-34373, is the same problem.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.