QID 150859
Date Published: 2024-04-08
QID 150859: WordPress ElementsKit Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2024-2803)
Elements Kit is an all in one advanced addon built to enhance the page builder with widgets and features.
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Versions:
WordPress Elements Kit Plugin before 3.1.0
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to inject arbitrary JavaScript code in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVEs related to QID 150859
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ElementsKit Elementor addons |
|