CVE-2024-1326
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-1326 is a recently disclosed vulnerability affecting the Jeg Elementor Kit plugin for WordPress. This issue allows authenticated attackers with contributor-level access and above to execute arbitrary web scripts by exploiting insufficient input sanitization and output escaping in HTML Tag attributes. The vulnerability persists in all versions up to and including 2.6.2. Successful exploitation enables attackers to inject malicious code that will execute whenever a user visits an injected page. This vulnerability poses a significant risk to WordPress sites running the Jeg Elementor Kit plugin and should be addressed promptly by applying the latest available patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.