CVE · Medium

CVE-2024-3728 — Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3728 Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.9.16 5.9.16 2024-04-24

CVE-2024-3728

The Essential Addons for Elementor plugin through version 5.9.15 contains a stored cross-site scripting vulnerability in its Filterable Gallery and Interactive Circle widgets. Attackers with contributor-level permissions or higher can inject malicious scripts into pages by exploiting inadequate sanitization and escaping of user-supplied attributes. When visitors load pages containing the injected code, the malicious scripts execute in their browsers. The vulnerability was fixed in version 5.9.16.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.