CVE · Medium

CVE-2024-1429 — Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1429 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.6.1 5.6.1 2024-04-17

CVE-2024-1429

The Element Pack Addons for Elementor plugin in versions up to 5.6.0 contains a stored cross-site scripting vulnerability in the Panel Slider widget's 'tab_link' attribute, which fails to properly sanitize input and escape output. Attackers with contributor-level permissions or higher can inject malicious scripts that execute when users view affected pages. The vulnerability was patched in version 5.6.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.