CVE-2024-5645
A vulnerability exists in the Envo Extra plugin for WordPress, specifically in versions up to 1.8.23, where an attacker with Contributor-level access or higher can inject malicious web scripts into pages through the 'button_css_id' parameter in the Button widget. This occurs due to inadequate input validation and output protection, allowing the attacker to inject arbitrary web scripts that will execute when accessed by other users. As a result, an attacker can potentially inject malicious code into pages, which can then be executed by unsuspecting users.
Based on public CVE data (MITRE/NVD).