CVE Database /
CVE-2024-11180
CVE · Medium
CVE-2024-11180 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.4.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-11180
|
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.4.8 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 3.4.8
|
3.4.8 |
2025-03-28 |
—
|
CVE-2024-11180
The ElementsKit Elementor addons plugin for WordPress contains a stored cross-site scripting vulnerability in the Countdown Timer Widget that affects versions 3.4.7 and earlier. The ekit_countdown_timer_title parameter fails to properly sanitize user input and escape output, allowing authenticated users with Contributor privileges or higher to inject malicious scripts into pages. When other users visit pages containing the injected code, the scripts execute in their browsers.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings