CVE · Medium

CVE-2024-4003 — Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4003 Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16 Improper Input Validation Medium 5.4 < 5.9.16 5.9.16 2024-04-24

CVE-2024-4003

The Essential Addons for Elementor plugin before version 5.9.16 contains a stored cross-site scripting vulnerability in the Team Members widget's eael_team_members_image_rounded parameter. Attackers with contributor-level access or higher can inject malicious scripts through this parameter because the plugin fails to properly sanitize input and escape output. When a user visits a page containing the injected code, the scripts execute in their browser, potentially compromising site security or user data.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.