CVE-2023-39157

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Dec 31, 2023
Updated: Jan 5, 2024
CWE ID 94

Summary

CVE-2023-39157 is a Code Injection vulnerability affecting JetElements For Elementor, a popular plugin used with the Elementor page builder. Versions from n/a to 2.6.10 are impacted. An attacker can exploit this vulnerability to inject malicious code, potentially leading to unauthorized access or data theft. The issue arises due to improper control over the code generation process within JetElements For Elementor. Users are urged to update to the latest version to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share