← back
CVE-2024-47626

WordPress RomethemeKit For Elementor plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 MEDIUMEPSS 0.2%CWE-79
In short

The WordPress RomethemeKit plugin for Elementor doesn't properly clean user inputs, allowing attackers to inject malicious scripts that get stored and executed when others view the page. This can compromise user accounts and steal sensitive data.

Technical detail

Stored XSS vulnerability in RTMKit <= 1.5.0 due to improper input sanitization during web page generation. An authenticated or unauthenticated attacker can inject malicious JavaScript that persists in the database and executes in victims' browsers, potentially leading to session hijacking, credential theft, or malware distribution.

Summary generated and translated by AI from the official description.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Stored XSS.This issue affects RTMKit: from n/a through <= 1.5.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Affected products
Rometheme · RTMKit

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →