CVE-2024-0904: Fancy Product Designer < 6.1.81 - Admin+ Cross Site Scripting
The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0904?
CVE-2024-0904 is considered a high-severity vulnerability due to its potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-0904?
To fix CVE-2024-0904, update the Fancy Product Designer WordPress plugin to version 6.1.81 or later.
Who is affected by CVE-2024-0904?
CVE-2024-0904 affects users of the Fancy Product Designer WordPress plugin versions prior to 6.1.81.
What type of attack does CVE-2024-0904 facilitate?
CVE-2024-0904 facilitates Stored Cross-Site Scripting attacks, allowing high privilege users to inject malicious scripts.
What should I do if I can't update the plugin due to compatibility issues?
If unable to update due to compatibility issues, consider disabling the Fancy Product Designer plugin until a safe solution is implemented.