CVE-2024-2347: Astra <= 4.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name
The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2347?
CVE-2024-2347 has a medium severity rating due to its potential for stored cross-site scripting vulnerabilities.
How do I fix CVE-2024-2347?
To fix CVE-2024-2347, update the Astra theme for WordPress to version 4.6.9 or later.
Who is affected by CVE-2024-2347?
Authenticated users with contributor-level access and above are affected by CVE-2024-2347.
What types of attacks can be executed via CVE-2024-2347?
CVE-2024-2347 allows attackers to inject malicious scripts into a user's display name, leading to potential cross-site scripting attacks.
Is CVE-2024-2347 present in earlier versions of the Astra theme?
Yes, CVE-2024-2347 is present in all versions of the Astra theme up to and including 4.6.8.