CVE-2024-4667

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post and Category Filter widget in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied 'post_types' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p><strong>Blog, Posts and Category Filter for Elementor</strong> lets you filter your Blog posts with Category. You can now display more posts to your users. Your users can now filter posts by category without reloading the page or going to the inner category page. It will save your users time and engage them with your website posts.</p> <blockquote> <p><strong><a href="https://plugin-devs.com/product/elementor-post-category-filter/" rel="nofollow ugc">Upgrade to Pro!</a></strong></p> </blockquote> <h3>Features</h3> <ul> <li>Choose Between <strong>Posts and Pages</strong></li> <li>Filter Posts with <strong>Categories</strong> related to Blog Posts</li> <li><strong>Category Selection</strong> to display Posts from only specific Category</li> <li><strong>Limit Posts</strong></li> <li><strong>Show or Hide Image</strong></li> <li>Choose <strong>Image Size</strong> from WordPress Registered <strong>Image Sizes</strong></li> <li><strong>Custom Image Size</strong></li> <li>Option to change <strong>Load More, Loading Texts</strong></li> <li>Fully <strong>Customizable Styling Options</strong> for filter buttons to customize the <strong>Color, Background, Border</strong></li> <li>Other <strong>Basic Customizable Styling Options</strong></li> <li>Extremely <strong>User Friendly</strong> settings panel for coders and non-coders alike.</li> <li>Unique Settings for every widgets.</li> <li>Support all Modern Browsers: <strong>Firefox, Chrome, IE, Safari etc</strong>.</li> <li>Unlimited Widgets on One Page</li> <li><strong>Custom CSS</strong></li> <li><strong>Free Basic Support.</strong><br /> &gt; <strong>More Features are Coming Soon</strong></li> </ul> <blockquote> <p><strong><a href="https://plugin-devs.com/product/elementor-post-category-filter/" rel="nofollow ugc">Upgrade to Pro!</a></strong></p> </blockquote> <p>There is also a <a href="https://plugin-devs.com/product/elementor-post-category-filter/" rel="nofollow ugc">Pro Version</a> of this plugin. You will get more features and advantages on the <a href="https://plugin-devs.com/product/elementor-post-category-filter/" rel="nofollow ugc">Pro Version</a>. <strong><a href="https://plugin-devs.com/product/elementor-post-category-filter/" rel="nofollow ugc">Blog, Posts and Category Filter for Elementor Pro</a></strong> is a multi-purpose responsive <strong>Post Showcase plugin</strong> that allows you to show more <strong>Posts (any post type)</strong>. It has plenty of extremely user-friendly options and supports <strong>Post, Custom Post, Taxonomy, Custom Taxonomy, Specific Posts, and more</strong>. You can fully <strong>Customize the Style</strong> with the <a href="https://plugin-devs.com/product/elementor-post-category-filter/" rel="nofollow ugc">PRO Version</a>.</p> <ul> <li>Choose Posts from <strong>Any Post Types (Including Custom Post Types, WooCommerce Products)</strong></li> <li>Filter Posts by <strong>Categories, Tags and Custom Taxonomies</strong> related to <strong>Blog Posts, and Custom Post Types</strong></li> <li>Filter From <strong>Category, Tags, </strong>and<strong> other Custom Taxonomies</strong> Related to the <strong>Chosen Post Type</strong></li> <li><strong>Limit Posts</strong></li> <li><strong>Show or Hide Image</strong></li> <li><strong> Introduce Ajax Filtering </strong> ***Most Popular</li> <li>Choose <strong>Image Size</strong> from WordPress Registered <strong>Image Sizes</strong></li> <li><strong>Custom Image Size</strong></li> <li><strong>Include Specific Post</strong> by Search from Chosen Post Type</li> <li><strong>Exclude Specific Post</strong> by Search from Chosen Post Type</li> <li><strong>Order Posts</strong> by <strong>Publish Date, ID, Post Title, Post Name, Modified Date, Random, Comment Count, and Menu Order</strong></li> <li><strong>Ordering Posts</strong> in <strong>Ascending or Descending Order</strong></li> <li>Filter Posts and Pages with <strong>Post Status</strong></li> <li><strong>Ignore Sticky Posts</strong></li> <li>Option to Add <strong>Multiple Rows</strong></li> <li><strong>Show or Hide Title</strong></li> <li><strong>Show or Hide Excerpt</strong></li> <li><strong>Show or Hide Read More Button</strong></li> <li>Option to <strong>Limit Words</strong></li> <li>Option to <strong>Limit Characters</strong></li> <li>Custom <strong>Load More Icons</strong> from <strong>Font Awesome Icon</strong> and <strong>SVG Icon</strong></li> <li>Custom <strong>Loading Icons</strong> from <strong>Font Awesome Icon</strong> and <strong>SVG Icon</strong></li> <li>Customizable Color, Hover, and Background Option to match the slider look with your taste and feel</li> <li>Option to change <strong>Read More Text</strong></li> <li>Option to change <strong>Load More Text</strong></li> <li>Option to change <strong>Loading Text</strong></li> <li><strong>Fully Customizable Style</strong></li> <li>Choose <strong>Spacing Between Items</strong></li> <li>Extremely <strong>User-Friendly</strong> settings panel for coders and non-coders alike.</li> <li>Unique Settings for every carousel.</li> <li>Support all Modern Browsers: <strong>Firefox, Chrome, IE, Safari, etc</strong>.</li> <li>Unlimited Widgets on One Page</li> <li><strong>Custom CSS</strong></li> <li><strong>Custom JS</strong></li> <li><strong>Priority Support</strong></li> <li>All Free Features</li> </ul> <blockquote> <p><strong><a href="https://plugin-devs.com/product/elementor-post-category-filter/" rel="nofollow ugc">Upgrade to Pro!</a></strong></p> </blockquote>
WordPress Plugin DirectoryWordPress Plugin Directory
29.7K