CVE-2024-4212
The Themesflat Addons For Elementor plugin contains a stored cross-site scripting vulnerability affecting multiple widgets including TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box through version 2.1.1. Authenticated users with contributor permissions or higher can inject malicious scripts into widget attributes due to inadequate input sanitization and output escaping. When site visitors access pages containing the injected widgets, the stored scripts execute in their browsers. The vulnerability has been fixed in version 2.1.3.
Based on public CVE data (MITRE/NVD).