CVE-2024-1234General(exclusiveaddons / exclusive_addons_for_elementor)

MEDIUMCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch exclusiveaddons exclusive_addons_for_elementor systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exclusive_addons_for_elementor

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • General: 5 classified signals
  • Disclosure: 4 classified signals
  • Peaked 6d ago at 4 mentions (2026-02-03); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Products
exclusive_addons_for_elementor

Deep dive

Activity timeline11 mentions / 8d
01234Mentions · 2026-01-27: 1Mentions · 2026-02-03: 4Mentions · 2026-02-24: 1Mentions · 2026-02-28: 1Mentions · 2026-03-07: 1Mentions · 2026-03-10: 1Mentions · 2026-07-03: 1Mentions · 2026-09-08: 1PoC Mentioned / Linked · 2026-03-07: 1Exploit Tool / Code · 2026-02-28: 1Exploit Tool / Code · 2026-03-07: 1Patch / Workaround · 2026-02-28: 1Technical Details · 2026-01-27: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-10: 101-2702-0302-2402-2803-0703-1007-0309-08
Signal classification3 categories
General
545.5%
Disclosure
436.4%
Exploit
218.2%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-02-034
Disclosure2General2
2026-02-241
General1
2026-02-281
Exploit1
2026-03-071
Exploit1
2026-03-101
Disclosure1
2026-07-031
General1
2026-09-081
General1
Full discourse11 posts
  • ExWareLabs@ExWareLabs
    Disclosure

    Clawdbot, Command Injection Vulnerability, #CVE-2024-1234 (Critical) https://t.co/N26MMNHf4u

    Post summary

    The tweet announces a critical command injection vulnerability (CVE-2024-1234) but provides no details on exploits, PoCs, or patches.

    220902.2K
    748 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-21509 2 - CVE-2026-20805 3 - CVE-2024-3094 4 - CVE-2024-1234 5 - CVE-2010-5139 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top five trending CVEs without offering any exploitation details, patches, or technical information.

    00020246
    1.7K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Exploit

    🚨 Unmasking the Latest MOVEit Transfer Zero-Day: A Deep Dive into the #CVE-2024-1234 SQLi Exploit and #Digital Forensics + Video https://undercodetesting.com/unmasking-the-latest-moveit-transfer-zero-day-a-deep-dive-into-the-cve-2024-1234-sqli-exploit-and-digital-forensics-video/ Educational Purposes!

    Post summary

    The tweet promotes an article that appears to provide a proof‑of‑concept SQL injection exploit for the newly disclosed MOVEit Transfer zero‑day CVE‑2024‑1234, though it makes no claim of active exploitation or mentions of patches.

    00001131
    404 followersView on X
  • David@davidsheyi
    Exploit

    2/ With CVE-2024-1234, attackers can deploy AirSnitch to intercept traffic via machine-in-the-middle attacks on public Wi-Fi. Patch your systems now! #InfoSec #DataBreach

    Post summary

    CVE‑2024‑1234 allows attackers to use AirSnitch for MITM attacks on public Wi‑Fi, and the post urges immediate patching.

    1000086
    556 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    General

    Poll CVEs from Python in 3 lines: import requests r = requests.get('https://api.valtersit.com/cve/CVE-2024-1234') print(r.json()) Metered API, no key setup friction. Docs at http://valtersit.com/cve/pricing #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #china #france #germany #docker #kali

    Post summary

    The post simply demonstrates how to query a CVE via an API, without mentioning POCs, exploits, active use, patches, or detailed vulnerability information.

    0000044
    1.0K followersView on X
  • scanninja.ai@scanninjaai
    General

    Your scanner says CVE-2024-1234 is closed. Your auditor asks: "Prove it" A ticket status or screenshot isn't evidence or verification. We re-scan the asset and shows the control gap closed, verifiable proof. Book a demo → https://scanninja.ai/demo #CyberSecurity #CISO https://t.co/isjWtroDu8

    Post summary

    The tweet states that a scanner reports CVE‑2024‑1234 as closed after a re‑scan, but offers no technical details, PoC, exploit code, patch information, or evidence of active exploitation.

    0000043
    15 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 (Hypothetical Library Name), Code Injection, #CVE-2024-1234 (Critical) https://dailycve.com/hypothetical-library-name-code-injection-cve-2024-1234-critical/

    Post summary

    The tweet announces a new critical code injection vulnerability (CVE-2024-1234) in (Hypothetical Library Name), directing readers to a detailed article.

    0000058
    167 followersView on X
  • Manish Verma🫎@ManishVermalion
    General

    Byte is sweeping the network with her blacklight nose! 🕵️‍♀️🔦 CVE-2024-1234? Detected. Missing patches? Flagged. She sniffs out weaknesses before the bad guys even wake up. #VulnerabilityManagement #InfoSec @DataHaven_xyz

    Post summary

    The post references CVE-2024-1234 but offers no technical details, exploit information, or mitigation steps.

    0000056
    1 followersView on X
  • VulnTracker@vuln_tracker
    General

    @ExWareLabs You now can see the full details about CVE-2024-1234 on http://Vulntracker.io

    Post summary

    The tweet points to a website for CVE-2024-1234 details but provides no additional information.

    00000108
    333 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Clawdbot, Command Injection Vulnerability, #CVE-2024-1234 (Critical) https://dailycve.com/clawdbot-command-injection-vulnerability-cve-2024-1234-critical/

    Post summary

    The post announces a critical command injection vulnerability (CVE‑2024‑1234) in Clawdbot, but does not provide PoC, exploitation details, or mitigation information.

    0000069
    162 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Hono, #IP Validation Bypass, #CVE-2024-1234 (Critical) https://dailycve.com/hono-ip-validation-bypass-cve-2024-1234-critical/

    Post summary

    A new critical CVE-2024-1234, identified as an IP Validation Bypass, has been announced and linked to a DailyCVE article.

    0000044
    162 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appexclusiveaddonsexclusive_addons_for_elementor-wordpress-

Explore more