CVE · Medium

CVE-2024-11180 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.4.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11180 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.4.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.4.8 3.4.8 2025-03-28

CVE-2024-11180

The ElementsKit Elementor addons plugin for WordPress contains a stored cross-site scripting vulnerability in the Countdown Timer Widget that affects versions 3.4.7 and earlier. The ekit_countdown_timer_title parameter fails to properly sanitize user input and escape output, allowing authenticated users with Contributor privileges or higher to inject malicious scripts into pages. When other users visit pages containing the injected code, the scripts execute in their browsers.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.