CVE-2023-24404: WordPress Marketing Performance Plugin <= 2.0.0 is vulnerable to Cross Site Scripting (XSS)
Published Apr 23, 2023
·Updated
Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions.
Affected Software
1 affected component
Rarathemes Vryasage Marketing Performance Wordpress<=2.0.0
Event History
Apr 23, 2023
CVE Published
via MITRE·09:45 AM
Data Sourced
via MITRE·09:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-24404?
CVE-2023-24404 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2023-24404?
To fix CVE-2023-24404, update the VryaSage Marketing Performance plugin to a version exceeding 2.0.0.
3
Who is affected by CVE-2023-24404?
The vulnerability affects users of the VryaSage Marketing Performance plugin version 2.0.0 and earlier.
4
What are the risks associated with CVE-2023-24404?
Exploiting CVE-2023-24404 can lead to unauthorized script execution in the context of the victim's browser.
5
Is CVE-2023-24404 a common vulnerability?
Reflected cross-site scripting vulnerabilities like CVE-2023-24404 are frequently encountered in web applications.