Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Grids Slicko slicko-for-elementor allows DOM-Based XSS.This issue affects Slicko: from n/a through <= 1.2.0.
Security readout for executives and security teams
Plain-English summary
CVE-2024-51591 is a medium-severity DOM-based cross-site scripting issue in the WordPress Slicko plugin for Elementor through version 1.2.0. A logged-in user and visitor interaction are required, but successful abuse could affect confidentiality, integrity, and availability at a limited level.
Executive priority
Treat this as a targeted WordPress hygiene item, not an emergency based on current evidence. Prioritize sites using Slicko, especially public-facing or multi-author sites, and require confirmation that affected versions are removed, disabled, or updated per vendor guidance.
Technical view
The issue is CWE-79 improper neutralization during web page generation in WP Grids Slicko slicko-for-elementor. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L, indicating network reachability, low attack complexity, required privileges, required user interaction, and changed scope.
Likely exposure
Exposure is limited to WordPress sites with the slicko-for-elementor plugin installed at version 1.2.0 or earlier. The bundle does not identify affected themes, hosting providers, or downstream packages beyond WP Grids Slicko.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation evidence. The CVSS vector indicates exploitation requires a low-privileged account and user interaction, so risk is higher on multi-user WordPress sites or sites with broad contributor access.
Researcher notes
Evidence is sparse beyond the CVE record and Patchstack entry. Do not assume a patch version from the provided bundle. Validation should focus on asset inventory, version confirmation, role exposure, and vendor advisory tracking rather than exploit reproduction.
Mitigation direction
Inventory WordPress sites for slicko-for-elementor installations.
Identify any Slicko plugin versions at or below 1.2.0.
Check Patchstack or vendor guidance for an available fixed release.
Disable or remove Slicko where it is not business-critical.
Limit WordPress roles able to configure plugin content.
Validation and detection
Confirm whether slicko-for-elementor is installed on each WordPress property.
Record the installed Slicko version and compare it to 1.2.0.
Review accounts with plugin or content-editing privileges.
Check change logs or vendor advisories before declaring remediation complete.
Monitor affected sites for unexpected script injection reports.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.