← Back to browse · API

CVE-2024-37091

Severity
CRITICAL
CVSS
9.9
EPSS
0.01243
Risk score
40.04
CISA KEV
No
PoC
No
Published
2024-06-24
Modified
2026-04-28
First seen
2026-08-07
Aliases
EUVD-2024-36421, GHSA-9CP8-PR92-VG9Q
Products
StylemixThemes:Consulting Elementor Widgets n/a ≤1.3.0, StylemixThemes:Masterstudy Elementor Widgets n/a ≤1.2.2
Sources
euvd EUVD-2024-36421

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0; Masterstudy Elementor Widgets: from n/a through 1.2.2.

References