CVE-2024-47629
CVE-2024-47629: Stored Cross-Site Scripting (XSS) vulnerability exists in BdThemes Ultimate Store Kit Elementor Addons versions up to 2.0.5. This flaw allows attackers to inject malicious scripts into web pages. The vulnerability stems from improper neutralization of input during web page generation. Although the CVSS score is 0, indicating minimal base severity, the SVRS score of 30 suggests a moderate level of risk depending on the specific context of use. A successful exploit could lead to account compromise, data theft, or redirection to malicious sites. Users of Ultimate Store Kit Elementor Addons are advised to update to a patched version to mitigate this risk, even with a low default score, contextual risk can be higher. This highlights the importance of considering both quantitative and qualitative risk assessments.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.