QID 150859

Date Published: 2024-04-08

QID 150859: WordPress ElementsKit Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2024-2803)

Elements Kit is an all in one advanced addon built to enhance the page builder with widgets and features.

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected Versions:
WordPress Elements Kit Plugin before 3.1.0

QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.

Successful exploitation of this vulnerability could allow an unauthenticated attacker to inject arbitrary JavaScript code in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

  • CVSS V3 rated as High - 6.4 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Customers are advised to upgrade to Elements Kit 3.1.0 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 150859

    Software Advisories
    Advisory ID Software Component Link
    ElementsKit Elementor addons URL Logo wordpress.org/plugins/elementskit-lite/#developers