CVE · Medium

CVE-2024-0326 — Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.19

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-0326 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.10.19 4.10.19 2024-02-14

CVE-2024-0326

Premium Addons for Elementor versions prior to 4.10.19 contain a cross-site scripting vulnerability that was discovered by Webbernaut. An attacker could exploit this flaw to inject arbitrary scripts into a website, enabling actions like malicious redirects, unwanted advertisements, or other HTML-based attacks that execute for site visitors. The issue has been patched in version 4.10.19 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.