CVE-2024-2619

Published May 16, 2024

Last updated 2 months ago

Overview

Description
The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.
Source
security@wordfence.com
NVD status
Modified
Products
elementor_header_\&_footer_builder

Risk scores

CVSS 3.1

Type
Primary
Base score
5.4
Impact score
2.7
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

security@wordfence.com
CWE-862
nvd@nist.gov
CWE-79

Social media

Hype score
Not currently trending

Configurations