CVE-2024-51584: WordPress Marquee Elementor with Posts plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anas2004 Marquee Elementor with Posts marquee-elementor allows DOM-Based XSS.This issue affects Marquee Elementor with Posts: from n/a through <= 1.2.0.
Security readout for executives and security teams
Plain-English summary
This WordPress plugin issue can let a low-privileged user cause malicious script to run in another user's browser after interaction. Business impact is usually site-account exposure, unwanted content changes, or limited disruption, not full server takeover based on the provided CVSS data.
Executive priority
Treat as a moderate web application risk. Prioritize internet-facing WordPress sites using this plugin, especially where many editors or contributors have access. It does not justify emergency response unless local evidence shows exploitation or sensitive administrative exposure.
Technical view
CVE-2024-51584 is a CWE-79 DOM-based XSS in anas2004 Marquee Elementor with Posts, package marquee-elementor, affecting versions through 1.2.0. CVSS 3.1 is 6.5: network reachable, low complexity, low privileges required, user interaction required, changed scope, and low confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to WordPress sites with Marquee Elementor with Posts installed at version 1.2.0 or earlier. The bundle does not prove broad deployment, default enablement, or exposure on sites without the plugin.
Exploitation context
The CVSS vector requires attacker privileges and victim interaction, which reduces urgency compared with unauthenticated XSS. The source bundle marks KEV as false and provides no cited evidence of active exploitation.
Researcher notes
Evidence is limited to the CVE record and Patchstack database reference. The bundle does not name a fixed version, exploit availability, affected code path details, or proof of exploitation. Avoid assuming impact beyond DOM-based XSS with low-privilege prerequisite and user interaction.
Mitigation direction
Inventory WordPress sites for the marquee-elementor plugin.
Check whether installed versions are 1.2.0 or earlier.
Review vendor or Patchstack guidance for a fixed version or mitigation.
Disable or remove the plugin where it is not required.
Limit plugin and Elementor editing access to trusted users.
Validation and detection
Confirm plugin presence and version from WordPress administration or asset inventory.
Identify pages or widgets using Marquee Elementor with Posts.
Review user roles allowed to edit affected content or settings.
Use safe staging validation to confirm XSS exposure without weaponized payloads.
Track remediation status per site and retest after updates or removal.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.