CVE Database /
CVE-2024-1997
CVE · Medium
CVE-2024-1997 — Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-1997
|
Premium Addons Pro for Elementor [premium-addons-pro] < 2.9.13 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.9.13
|
2.9.13 |
2024-03-07 |
—
|
CVE-2024-1997
The Premium Addons PRO plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions up to 2.9.12 in the Messenger Chat Widget's 'premium_fbchat_app_id' parameter. Attackers with contributor privileges or higher can exploit insufficient sanitization and escaping to inject malicious scripts that execute for all users viewing affected pages. The vulnerability requires authentication but allows contributors to compromise website security by injecting arbitrary JavaScript code. Fixed in version 2.9.13.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings