Vulnerabilities > Wpzoom > Wpzoom Addons FOR Elementor > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-20 CVE-2024-5686 Cross-site Scripting vulnerability in Wpzoom Addons for Elementor
The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Team Members widget in all versions up to, and including, 1.1.38 due to insufficient input sanitization and output escaping.
network
low complexity
wpzoom CWE-79
5.4