CVE-2024-22148: WordPress WP Smart Editor Plugin <= 1.3.3 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Editor JoomUnited allows Reflected XSS.This issue affects JoomUnited: from n/a through 1.3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22148?
CVE-2024-22148 has a moderate severity rating due to its potential for exploitation via reflected Cross-site Scripting (XSS).
How do I fix CVE-2024-22148?
To fix CVE-2024-22148, update the WP Smart Editor plugin to the latest version or at least to version 1.3.4, if available.
What versions of WP Smart Editor are affected by CVE-2024-22148?
CVE-2024-22148 affects all versions of WP Smart Editor up to and including version 1.3.3.
Is CVE-2024-22148 a type of Cross-site Scripting vulnerability?
Yes, CVE-2024-22148 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
What impact does CVE-2024-22148 have on users?
CVE-2024-22148 could allow an attacker to execute malicious scripts in the context of a user's session, leading to potential data theft or account compromise.