CVE-2024-4666
Last modified
CVE-2024-4666 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Visualmodo | Borderless | < 1.5.4 |
References
- https://wordpress.org/plugins/borderless/#developersRelease Notes
- https://wordpress.org/plugins/borderless/#developersRelease Notes
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-4666?
How severe is CVE-2024-4666?
How do I fix CVE-2024-4666?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4665The EventPrime WordPress plugin before 3.5.0 does not proper…6.4
- CVE-2024-46652Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability …9.8
- CVE-2024-46654A stored cross-site scripting (XSS) vulnerability in the Add…4.8
- CVE-2024-46655A reflected cross-site scripting (XSS) vulnerability in Elle…6.1
- CVE-2024-46657Artifex Software mupdf v1.24.9 was discovered to contain a s…5.5
- CVE-2024-46658Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to co…8
- CVE-2024-46662A improper neutralization of special elements used in a comm…8.8
- CVE-2024-46663A stack-buffer overflow vulnerability [CWE-121] in Fortinet …6.7
- CVE-2024-46664A relative path traversal in Fortinet FortiRecorder [CWE-23]…4.9
- CVE-2024-46665An insertion of sensitive information into sent data vulnera…3.7
- CVE-2024-46666An allocation of resources without limits or throttling [CWE…5.3
- CVE-2024-46667A allocation of resources without limits or throttling in Fo…7.5
Are you affected by CVE-2024-4666?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
