CVE-2024-10980

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:bdthemes:element_pack:*:*:*:*:lite:wordpress:*:*

History

07 May 2025, 00:03

Type Values Removed Values Added
First Time Bdthemes
Bdthemes element Pack
References () https://wpscan.com/vulnerability/915daad8-d14c-4457-a3a0-aa21744f4ae0/ - () https://wpscan.com/vulnerability/915daad8-d14c-4457-a3a0-aa21744f4ae0/ - Exploit, Third Party Advisory
CWE CWE-79
CPE cpe:2.3:a:bdthemes:element_pack:*:*:*:*:lite:wordpress:*:*

29 Nov 2024, 15:15

Type Values Removed Values Added
Summary
  • (es) El complemento Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) de WordPress anterior a la versión 5.10.3 no valida ni escapa algunas de sus opciones de bloque de consentimiento de cookies antes de mostrarlas nuevamente en una página o publicación donde el bloque está incrustado, lo que podría permitir a los usuarios con el rol de colaborador y superior realizar ataques de Cross-Site Scripting almacenado.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

29 Nov 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-29 06:15

Updated : 2025-05-07 00:03


NVD link : CVE-2024-10980

Mitre link : CVE-2024-10980

CVE.ORG link : CVE-2024-10980


JSON object : View

Products Affected

bdthemes

  • element_pack
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')