CVE-2024-51590: WordPress Hoo Addons for Elementor plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HooThemes Hoo Addons for Elementor hoo-addons-for-elementor allows DOM-Based XSS.This issue affects Hoo Addons for Elementor: from n/a through <= 1.0.6.
Security readout for executives and security teams
Plain-English summary
CVE-2024-51590 is a medium-severity cross-site scripting flaw in the WordPress Hoo Addons for Elementor plugin through version 1.0.6. A logged-in attacker could potentially cause script execution in another user’s browser after user interaction, creating limited risk to data, site content, or session integrity.
Executive priority
Treat this as a moderate WordPress application risk. Prioritize sites with public registration, many contributors, or sensitive admin workflows. There is no provided evidence of active exploitation, but affected sites should be inventoried and remediated through vendor guidance or plugin removal.
Technical view
The CVE describes improper input neutralization during web page generation, classified as CWE-79 DOM-based XSS. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L, meaning exploitation is network-reachable but requires low privileges and victim interaction. The bundle does not name a fixed version.
Likely exposure
Exposure is limited to WordPress sites running HooThemes Hoo Addons for Elementor versions up to and including 1.0.6. Sites without this plugin, or running versions outside the affected range, are not indicated as affected by the provided sources.
Exploitation context
The source bundle does not show CISA KEV listing, active exploitation, public exploit code, or confirmed in-the-wild attacks. Risk is higher where untrusted users can authenticate to WordPress or influence plugin-rendered content viewed by administrators or editors.
Researcher notes
Evidence supports DOM-based XSS in Hoo Addons for Elementor through 1.0.6, but the bundle lacks sink/source detail, proof-of-concept information, and a named fixed release. Validation should remain version- and configuration-focused unless vendor advisories provide safe test guidance.
Mitigation direction
Inventory WordPress sites for Hoo Addons for Elementor installation and version.
Check HooThemes and Patchstack guidance for an official fixed version or mitigation.
Disable or remove the plugin where business impact is acceptable.
Limit WordPress accounts to trusted users with least privilege.
Monitor admin sessions and content changes for suspicious activity.
Validation and detection
Confirm whether hoo-addons-for-elementor is installed on each WordPress site.
Verify the installed plugin version is not 1.0.6 or earlier.
Review vendor and Patchstack records for fix availability.
Check whether untrusted users have WordPress login access.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.