Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mayur Somani, threeroutes media Elegant Themes Icons allows Stored XSS.This issue affects Elegant Themes Icons: from n/a through 1.3.
                
            References
                    Configurations
                    History
                    31 Jul 2025, 18:42
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:wpai:elegant_themes_icons:*:*:*:*:*:wordpress:*:* | |
| First Time | 
        
        Wpai
         Wpai elegant Themes Icons  | 
21 Nov 2024, 09:23
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://patchstack.com/database/vulnerability/elegant-themes-icons/wordpress-elegant-themes-icons-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve - Third Party Advisory | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 6.5  | 
26 Jul 2024, 13:27
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://patchstack.com/database/vulnerability/elegant-themes-icons/wordpress-elegant-themes-icons-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve - Third Party Advisory | |
| CPE | cpe:2.3:a:threeroutesmedia:elegant_themes_icons:*:*:*:*:*:wordpress:*:* | |
| First Time | 
        
        Threeroutesmedia
         Threeroutesmedia elegant Themes Icons  | 
|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 5.4  | 
22 Jul 2024, 13:00
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
22 Jul 2024, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-07-22 10:15
Updated : 2025-07-31 18:42
NVD link : CVE-2024-37100
Mitre link : CVE-2024-37100
CVE.ORG link : CVE-2024-37100
JSON object : View
Products Affected
                wpai
- elegant_themes_icons
 
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
