VYPR
Medium severity6.5NVD Advisory· Published Oct 6, 2024· Updated Apr 23, 2026

CVE-2024-44024

CVE-2024-44024

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Medical Addon for Elementor medical-addon-for-elementor allows Stored XSS.This issue affects Medical Addon for Elementor: from n/a through <= 1.6.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Medical Addon for Elementor plugin allows authenticated attackers to inject malicious scripts; affects versions up to 1.6.4.

The Medical Addon for Elementor WordPress plugin suffers from a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation. This affects all versions up to and including 1.6.4 [1].

An attacker with elevated privileges (such as a contributor or higher) can inject arbitrary JavaScript into plugin elements. When other users or visitors view the affected page, the injected script executes in their browsers. No user interaction beyond visiting the page is required for the stored payload to trigger [1].

Successful exploitation allows the attacker to perform actions on behalf of the victim, such as redirecting to malicious sites, injecting advertisements, or stealing session cookies. This can lead to further compromise of the WordPress site and its users [1].

The vulnerability has been fixed in a newer version of the plugin. Users are strongly advised to update to version 1.6.5 or later to mitigate the risk. The Patchstack advisory provides additional details [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.