CVE Database /
CVE-2024-3190
CVE · Medium
CVE-2024-3190 — Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3190
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.6
|
< 1.5.108
|
1.5.108 |
2024-05-29 |
—
|
CVE-2024-3190
The Unlimited Elements For Elementor plugin contains a stored cross-site scripting vulnerability in its text field widget affecting versions up to 1.5.107, arising from inadequate sanitization and escaping of user-supplied attributes. Attackers with contributor-level permissions or higher can exploit this flaw to inject malicious scripts into pages, which then execute when visitors view the affected content. The vulnerability originates from handling of external templates. Version 1.5.108 and later include fixes for this issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings