Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • TikTok Shop Campaigns Driving Growth for Pet Product Brands
    • Top TikTok Shop Campaigns Changing the Baby and Kids’ Products Industry
    • Top TikTok Shop Campaigns Reshaping Marketing for Gaming & eSports Brands
    • Lead Capture Pages: Secrets Behind Boasting Signups
    • Hailey Bieber’s Rhode Skincare to Launch at Sephora Stores Across the U.S.
    • How Rhode Skincare Built a Scalable Creator Ecosystem I Traackr
    • Mastering Email Nurturing: Strategies, Sequences, and Software To Grow Customer Relationships
    • Top TikTok Shop Campaigns That Are Making Jewelry Brands Shine
    YGLuk
    • Home
    • MsLi
      • MsLi’s Digital Products
      • MsLi’s Social Connections
    • Tiktok Specialist
    • TikTok Academy
    • Digital Marketing
    • Influencer Marketing
    • More
      • SEO
      • Digital Marketing Tips
      • Email Marketing
      • Content Marketing
      • SEM
      • Website Traffic
      • Marketing Trends
    YGLuk
    Home » SEO
    SEO

    WordPress Elementor Addons Vulnerability Affects 400k Sites

    YGLukBy YGLukNovember 12, 2024No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Wordfence issued an advisory on a vulnerability patched within the fashionable Pleased Addons for Elementor plugin, put in on over 400,000 web sites. The safety flaw may enable attackers to add malicious scripts that execute when browsers go to affected pages.

    Pleased Addons for Elementor

    The Pleased Addons for Elementor plugin extends the Elementor web page builder with dozens of free widgets and options like picture grids, a consumer suggestions and evaluations perform, and customized navigation menus. A paid model of the plugin provides much more design functionalities that make it straightforward to create purposeful and engaging WordPress web sites.

    Saved Cross-Web site Scripting (Saved XSS)

    Saved XSS is a vulnerability usually happen when a theme or plugin doesn’t correctly filter consumer inputs (referred to as sanitization), permitting malicious scripts to be uploaded to the database and saved on the server itself. When a consumer visits the web site the script downloads to the browser and executes actions like stealing browser cookies or redirecting the consumer to a malicious web site.

    The saved XSS vulnerability affecting the Pleased Addons for Elementor plugin requires a hacker buying Contributor-level permissions (authentication), making it more durable to reap the benefits of the vulnerability.

    WordPress safety firm Wordfence rated the vulnerability 6.4 on a scale of 1 – 10, a medium menace stage.

    In accordance Wordfence:

    “The Pleased Addons for Elementor plugin for WordPress is susceptible to Saved Cross-Web site Scripting by way of the before_label parameter within the Picture Comparability widget in all variations as much as, and together with, 3.12.5 on account of inadequate enter sanitization and output escaping. This makes it doable for authenticated attackers, with Contributor-level entry and above, to inject arbitrary internet scripts in pages that may execute each time a consumer accesses an injected web page.”

    Plugin customers ought to contemplate updating to the most recent model, at the moment 3.12.6, which accommodates a safety patch for the vulnerability.

    Learn the Wordfence advisory:

    Happy Addons for Elementor <= 3.12.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison

    Featured Picture by Shutterstock/Purple Cristal



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    YGLuk
    • Website

    Related Posts

    Using Google Merchant Center Next For Competitive Analysis

    December 2, 2024

    The Definitive Guide For Your Online Store

    December 2, 2024

    Bluesky Emerges As Traffic Source: Publishers Report 3x Engagement

    December 2, 2024

    Google Chrome site engagement service metrics

    December 2, 2024
    Add A Comment
    Leave A Reply Cancel Reply

    three + 20 =

    Top Posts

    TikTok Shop Campaigns Driving Growth for Pet Product Brands

    June 1, 2025

    Top TikTok Shop Campaigns Changing the Baby and Kids’ Products Industry

    June 1, 2025

    Top TikTok Shop Campaigns Reshaping Marketing for Gaming & eSports Brands

    May 31, 2025

    Lead Capture Pages: Secrets Behind Boasting Signups

    May 31, 2025

    Hailey Bieber’s Rhode Skincare to Launch at Sephora Stores Across the U.S.

    May 30, 2025
    Categories
    • Content Marketing
    • Digital Marketing
    • Digital Marketing Tips
    • Email Marketing
    • Influencer Marketing
    • Marketing Trends
    • SEM
    • SEO
    • TikTok Academy
    • Tiktok Specialist
    • Website Traffic
    About us

    Welcome to YGLuk.com – Your Gateway to Digital Success!

    At YGLuk, we are passionate about the ever-evolving world of Digital Marketing and Influencer Marketing. Our mission is to empower businesses and individuals to thrive in the digital landscape by providing valuable insights, expert advice, and the latest trends in the dynamic realm of online marketing.

    We are committed to providing valuable, reliable, and up-to-date information to help you navigate the digital landscape successfully. Whether you are a seasoned professional or just starting, YGLuk is your one-stop destination for all things digital marketing and influencer marketing.

    Top Insights

    TikTok Shop Campaigns Driving Growth for Pet Product Brands

    June 1, 2025

    Top TikTok Shop Campaigns Changing the Baby and Kids’ Products Industry

    June 1, 2025

    Top TikTok Shop Campaigns Reshaping Marketing for Gaming & eSports Brands

    May 31, 2025
    Categories
    • Content Marketing
    • Digital Marketing
    • Digital Marketing Tips
    • Email Marketing
    • Influencer Marketing
    • Marketing Trends
    • SEM
    • SEO
    • TikTok Academy
    • Tiktok Specialist
    • Website Traffic
    Copyright © 2024 Ygluk.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.