CVE-2024-1235
MediumVulnerability Description
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom class field in all versions up to, and including, 8.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Known Affected Software
101 configuration(s) from 1 vendor(s)
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.9.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.14:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.10.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.7.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.9.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.15:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.0.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.2.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.9.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.2.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:5.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:5.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.7.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.10:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.9.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.9.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.12:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.5.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.9.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.9.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.1.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:5.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.3.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.9.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.7.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:3.0.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.5.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.3.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.3.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.2.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.9.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.7.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.10.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.01:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.16:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.11:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.9.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:1.2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.2.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.6.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.13:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.3.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.9.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.7.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.7.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:4.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.0.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.1.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:5.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:6.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:7.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:2.3.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:livemeshelementor:addons_for_elementor:8.2.2:*:*:*:*:wordpress:*:*
References & Resources
-
https://plugins.trac.wordpress.org/browser/addons-for-elementor/trunk/templates/addons/device-slider/loop.php#L33security@wordfence.com Product
-
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3032737%40addons-for-elementor%2Ftrunk&old=3026261%40addons-for-elementor%2Ftrunk&sfp_email=&sfph_mail=security@wordfence.com Patch Product
-
https://www.wordfence.com/threat-intel/vulnerabilities/id/70bda4b7-e442-4956-b3cb-8df96043bcde?source=cvesecurity@wordfence.com Third Party Advisory
-
https://plugins.trac.wordpress.org/browser/addons-for-elementor/trunk/templates/addons/device-slider/loop.php#L33af854a3a-2127-422b-91ae-364da2661108 Product
-
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3032737%40addons-for-elementor%2Ftrunk&old=3026261%40addons-for-elementor%2Ftrunk&sfp_email=&sfph_mail=af854a3a-2127-422b-91ae-364da2661108 Patch Product
-
https://www.wordfence.com/threat-intel/vulnerabilities/id/70bda4b7-e442-4956-b3cb-8df96043bcde?source=cveaf854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
Severity Details
Key Information
- Published Date
- February 29, 2024
Related News Articles
Latest news and updates about CVE-2024-1235
