CVE-2024-1237
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versions up to, and including, 1.6.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attack Parameters
Technical Impact
Time Line
Key Metrics
Recommended Solution
Related News Articles
2 article(s) mentioning this vulnerability
Vulnérabilités Sévères Identifiées dans le Serveur Git MCP d'Anthropic
Vulnérabilités sévères identifiées dans le serveur Git MCP d'Anthropic. Action immédiate requise pour prévenir les accès non autorisés et l'exécution…
Serious Security Flaws Identified in Anthropic's MCP Git Server
Serious security flaws have been identified in Anthropic's mcp-server-git, a critical Git server. Immediate action is required to prevent data…
Immediate Action Plan
1. Inventory
Identify all affected systems in your infrastructure.
2. Assessment
Assess exposure and criticality for your organization.
3. Mitigation
Apply patches or available workarounds.
4. Verification
Test and confirm effectiveness of applied measures.
