CVE-2024-23508: WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins PDF Poster – PDF Embedder Plugin for WordPress allows Reflected XSS.This issue affects PDF Poster – PDF Embedder Plugin for WordPress: from n/a through 2.1.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bPlugins PDF Poster – PDF Embedder Plugin for WordPressto a version that resolves this vulnerability.Fixed in 2.1.18
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23508?
CVE-2024-23508 is classified as a Reflected Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2024-23508?
To fix CVE-2024-23508, update the PDF Poster – PDF Embedder Plugin for WordPress to version 2.1.18 or later.
Which versions are affected by CVE-2024-23508?
CVE-2024-23508 affects the PDF Poster – PDF Embedder Plugin for WordPress versions up to and including 2.1.17.
What type of vulnerability is CVE-2024-23508?
CVE-2024-23508 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as XSS.
Who is impacted by CVE-2024-23508?
Users of the PDF Poster – PDF Embedder Plugin for WordPress versions up to 2.1.17 are impacted by CVE-2024-23508.