Hosting • Web • Marketing

Essential Addons for Elementor <= 5.9.23 – 6.4 vulnerability

The CourseVector team is always hard at work providing managed hosting, frequently stepping in to fix issues for our clients. Recently, we addressed a significant vulnerability in the Essential Addons for Elementor plugin, specifically a stored cross-site scripting (XSS) issue identified as CVE-2024-5189. This flaw, present in versions up to 5.9.23, allowed authenticated users with Contributor-level access to inject malicious scripts via the ‘custom_js’ parameter. Our proactive approach ensures that these vulnerabilities are swiftly resolved, maintaining the security and performance of our clients’ websites. We report these fixes to keep our clients informed and confident in our continuous efforts to protect their online presence.

Happy Holidays!

With the holiday season upon us our staff will be taking some time to relax and enjoy time with their families.

We may be a bit slower to respond during this period. If you haven’t gotten a response within 24 hours during our normal business hours, please use our support request form and indicate it is an emergency and someone will get back to you quickly.

 

Search

Sign Up for Our Newsletter

Thank you for your interest in our newsletter! Fill in the form below to receive periodic updates on internet and website security, free cybersecurity posters, WordPress news, and more!

"*" indicates required fields

Name*

Your privacy is important to us. We do not share your information with anyone. You can opt out of our newsletter at any time.

Stay up to date with technology, scams, WordPress, and more. Follow CourseVector on Facebook today!