CVE-2024-4373
CVE-2024-4373 describes a Stored Cross-Site Scripting (XSS) vulnerability in the Sina Extension for Elementor WordPress plugin, affecting all versions up to and including 3.5.3. This flaw, specifically within the Sina Particle Layer widget, stems from inadequate input sanitization and output escaping of user-supplied attributes. Authenticated attackers with contributor-level access or higher can inject malicious web scripts into pages, which then execute when a user views the compromised page. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low impact to confidentiality and integrity. While the EPSS score is low, suggesting a low probability of exploitation, the FAUCET Risk Score is 24/100. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The CVE has garnered minimal community discussion and media coverage, suggesting it is not a high-profile threat at this time.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.4CPE matchmatch criteria | cpe:2.3:a:sinaextra:sina_extension_for_elementor:*:*:*:*:*:wordpress:*:* |
CVSS Data
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Exploit Intelligence
Social Chatter
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation
Remediation records are not available for this CVE.