CVE-2024-1234
MediumVulnerability Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Known Affected Software
108 configuration(s) from 1 vendor(s)
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.6:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.41:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.90:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.81:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.1.6:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.4:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.4:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.3.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.3:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.9:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.3.0:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.7:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.5:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.5:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.85:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.4:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.1.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.7:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.5:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.5.0:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.7:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.6:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.70:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.42:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.3:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.31:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.1.4:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.3.3:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.93:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.9:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.9:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.8:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.2.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.50:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.4:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.71:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.0.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.9:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.92:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.5:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.61:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.91:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.0.8:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.3:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.90:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.7:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.1.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.8:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.80:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.0:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.5:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.6:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.3:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.4:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.0.6:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.95:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.2.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.40:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.82:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.5:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.1.5:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.81:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.0.7:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.8:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.1:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.60:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.6:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.8:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.6:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.83:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.62:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.2.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.0.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.8:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.1.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.0.9:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.6:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.30:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.4.61:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.7:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.0:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.3:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.3.84:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.0.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.1:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.6.7:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.2.3:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.2:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.1.3:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.1.2:*:*:*:free:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:1.4.4:*:*:*:pro:wordpress:*:*
cpe:2.3:a:exclusiveaddons:exclusive_addons_for_elementor:2.5.8:*:*:*:free:wordpress:*:*
References & Resources
-
https://plugins.trac.wordpress.org/changeset/3042217/exclusive-addons-for-elementorsecurity@wordfence.com Patch
-
https://www.wordfence.com/threat-intel/vulnerabilities/id/1b87fe3d-a88d-477a-8d91-4d7c2dba4a43?source=cvesecurity@wordfence.com Third Party Advisory
-
https://plugins.trac.wordpress.org/changeset/3042217/exclusive-addons-for-elementoraf854a3a-2127-422b-91ae-364da2661108 Patch
-
https://www.wordfence.com/threat-intel/vulnerabilities/id/1b87fe3d-a88d-477a-8d91-4d7c2dba4a43?source=cveaf854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
Severity Details
Key Information
- Published Date
- March 13, 2024
Related News Articles
Latest news and updates about CVE-2024-1234
