CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-4564

Medium Severity
34
SVRS
6.4
CVSSv3
0.00402
EPSS
TAGS
In The Wild
VECTOR STRING
CVSS:3.1AV:NAC:LPR:LUI:NS:CC:LI:LA:N
PUBLICATION DATE2024-06-12
LAST MODIFIED2026-04-08

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-4564, is a Stored Cross-Site Scripting (XSS) flaw affecting the CoDesigner WooCommerce Builder for Elementor WordPress plugin. It matters because it allows authenticated attackers, specifically those with contributor-level access or higher, to inject malicious web scripts into web pages. These scripts will then execute in the browsers of other users who visit the compromised pages. This can lead to various client-side attacks such as session hijacking, defacement, redirection to malicious sites, or theft of sensitive user data, severely impacting the integrity and confidentiality of the affected WordPress site and its users.
2. What are the CVSS score, severity level, and disclosure details?
The CVSS score for this vulnerability is 6.4. Based on common CVSS v3 interpretations, this corresponds to a Medium severity level. The vulnerability was publicly disclosed (published) on June 12, 2024, at 03:33:14 UTC. The information regarding this CVE was last modified on April 8, 2026, at 16:45:00 UTC.
3. Which products, vendors, systems, and versions are affected?
  • Product: CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More
  • Vendor: The developer of the CoDesigner WooCommerce Builder for Elementor plugin.
  • System/Platform: WordPress
  • Affected Versions: All versions up to, and including, 4.4.1. This means versions 4.4.1 and earlier are vulnerable.
4. What is the technical root cause and attack vector?
The technical root cause of CVE-2024-4564 is insufficient input sanitization and output escaping on user-supplied attributes within the plugin's Shop Slider, Tabs Classic, and Image Comparison widgets. This failure allows malicious script code to be stored persistently within the website's database and subsequently rendered without proper neutralization. The attack vector involves an authenticated attacker with at least contributor-level access leveraging these vulnerable widgets to inject arbitrary web scripts into pages.
5. How can this vulnerability be exploited?
An authenticated attacker with contributor-level or higher permissions can exploit this vulnerability by crafting and injecting malicious script payloads into the vulnerable Shop Slider, Tabs Classic, or Image Comparison widgets provided by the CoDesigner plugin. Due to the lack of proper input sanitization and output escaping, these malicious scripts are stored in the website's database. When an unsuspecting user, including administrators, subsequently accesses a page containing one of these compromised widgets, the injected script will execute within their web browser, leading to client-side attacks.
6. What mitigation steps and patches are available?
The primary mitigation step is to update the "CoDesigner WooCommerce Builder for Elementor" plugin to a version beyond 4.4.1, as the vulnerability affects "all versions up to, and including, 4.4.1." Users should consult the official plugin changelog or update channels for the specific patched version that addresses this vulnerability. If an immediate update is not possible, minimizing user accounts with contributor-level access or higher, especially for untrusted individuals, can reduce the attack surface.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by identifying the installed version of the "CoDesigner WooCommerce Builder for Elementor" plugin. Any installation running version 4.4.1 or earlier is considered vulnerable to CVE-2024-4564. System administrators can check the plugin version through the WordPress admin dashboard (Plugins > Installed Plugins) or by directly examining the plugin's version file on the server.
8. What are the indicators of compromise (IOCs)?
Information on specific Indicators of Compromise (IOCs) for CVE-2024-4564 is not explicitly provided in the given CVE data. However, potential signs of compromise could include:
  • Unexpected scripts or unusual content appearing on website pages that utilize the Shop Slider, Tabs Classic, or Image Comparison widgets.
  • Unusual network requests originating from user browsers when visiting potentially affected pages.
  • Unauthorized changes to website content, user accounts, or other administrative settings, particularly if a sophisticated XSS payload was used for session hijacking or privilege escalation.
9. Which threat actors are known to exploit this vulnerability?
The provided CVE data does not specify any known threat actors currently exploiting or historically associated with CVE-2024-4564.
10. What public intelligence references and advisories exist?
The primary public intelligence reference for this vulnerability is its Common Vulnerabilities and Exposures (CVE) identifier: CVE-2024-4564. Further detailed advisories and analyses would typically be found on the National Vulnerability Database (NVD) once the CVE is fully published there, as well as on the plugin vendor's official security advisories or changelog.
11. What is the risk assessment and urgency level?
The risk assessment for CVE-2024-4564 is Medium, as indicated by its CVSS score of 6.4. While exploitation requires an authenticated attacker with at least contributor-level access, the impact of a successful Stored XSS attack can be significant, potentially leading to client-side code execution, session hijacking, data theft, and website defacement. The urgency level is Moderate to High. Organizations using the affected plugin should prioritize updating to a patched version immediately. Although it requires authentication, the widespread use of WordPress and the Elementor ecosystem, combined with potentially numerous users having contributor or higher roles, increases the likelihood and potential impact of exploitation. Therefore, timely remediation is crucial to prevent unauthorized script execution and protect user data and website integrity.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

No tweets found for this CVE

No affected software found for this CVE

ReferenceLink
[email protected]https://plugins.trac.wordpress.org/browser/woolementor/trunk/widgets/image-comparison/image-comparison.php#L418
[email protected]https://plugins.trac.wordpress.org/browser/woolementor/trunk/widgets/shop-slider/template.php#L29
[email protected]https://plugins.trac.wordpress.org/browser/woolementor/trunk/widgets/tabs-classic/tabs-classic.php#L329
[email protected]https://plugins.trac.wordpress.org/changeset/3099922/
[email protected]https://wordpress.org/plugins/woolementor/#developers
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/3115e8ad-8e68-41e9-a3a0-5f003d921037?source=cve
AF854A3A-2127-422B-91AE-364DA2661108https://wordpress.org/plugins/woolementor/%23developers
AF854A3A-2127-422B-91AE-364DA2661108https://www.wordfence.com/threat-intel/vulnerabilities/id/3115e8ad-8e68-41e9-a3a0-5f003d921037?source=cve
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/3115e8ad-8e68-41e9-a3a0-5f003d921037?source=cve
AF854A3A-2127-422B-91AE-364DA2661108https://www.wordfence.com/threat-intel/vulnerabilities/id/3115e8ad-8e68-41e9-a3a0-5f003d921037?source=cve
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/3115e8ad-8e68-41e9-a3a0-5f003d921037?source=cve
CWE IDCWE NameDescription
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.