CVE-2024-0838
CVE-2024-0838 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Happy Addons for Elementor plugin for WordPress. The flaw exists in versions up to 3.10.1 and stems from insufficient input sanitization of the side image URL parameter within the Age Gate feature. Authenticated attackers with contributor access or higher can inject malicious web scripts into WordPress pages. When users access these compromised pages, the injected scripts execute. With an SVRS score of 30, this vulnerability poses a moderate risk. This vulnerability is significant because it allows attackers to potentially steal sensitive information or perform unauthorized actions within the WordPress site. While the CVSS score is moderate, successful exploitation could lead to account compromise and website defacement.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.