CVE-2024-4482
CVE-2024-4482: Stored Cross-Site Scripting (XSS) vulnerability in The Plus Addons for Elementor WordPress plugin. This flaw allows attackers to inject malicious scripts into pages via the 'Countdown' widget. The vulnerability exists due to insufficient input sanitization of the 'text_days' attribute, affecting versions up to 5.6.1. Authenticated attackers with contributor-level access can exploit this to execute arbitrary web scripts when users access the infected pages. Despite a moderate CVSS score of 5.4, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a lower immediate risk compared to more critical vulnerabilities. Successful exploitation could lead to session hijacking, defacement, or redirection to malicious sites. While not considered critical, patching this vulnerability is essential to maintain the security of your WordPress site.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.