CVE-2024-0905: Fancy Product Designer < 6.1.8 - Reflected Cross Site Scripting
Published Apr 26, 2024
·Updated
The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users
Affected Software
2 affected components
Fancy Product Designer Fancy Product Designer<6.1.8
Radykal Fancy Product Designer Wordpress<6.1.8
Event History
Apr 26, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-0905?
CVE-2024-0905 has a moderate severity level due to its potential for Reflected Cross-Site Scripting attacks.
2
How do I fix CVE-2024-0905?
To mitigate CVE-2024-0905, update the Fancy Product Designer WordPress plugin to version 6.1.8 or later.
3
Who is affected by CVE-2024-0905?
CVE-2024-0905 affects both unauthenticated users and admin-level users of the Fancy Product Designer plugin.
4
What type of vulnerability is CVE-2024-0905?
CVE-2024-0905 is classified as a Reflected Cross-Site Scripting vulnerability.
5
What versions of Fancy Product Designer are impacted by CVE-2024-0905?
CVE-2024-0905 impacts versions of the Fancy Product Designer plugin before 6.1.8.