漏洞描述
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) versions up to 1.5.93 contain a reflected cross-site scripting caused by improper neutralization of input during web page generation, letting attackers execute malicious scripts in the victim's browser, exploit requires attacker to craft a malicious URL.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2024-29792↗www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unlimited-elements-for-elementor/unlimited-elements-for-elementor-1593-reflected-cross-site-scripting↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset/3057553/unlimited-elements-for-elementor↗