First published: Sat Feb 10 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPoperation Ultra Companion – Companion plugin for WPoperation Themes allows Stored XSS.This issue affects Ultra Companion – Companion plugin for WPoperation Themes: from n/a through 1.1.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpoperation Ultra Companion | <=1.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24803 has a medium severity rating due to the risk of Stored Cross-site Scripting (XSS) exploits.
To fix CVE-2024-24803, update the Ultra Companion – Companion plugin for WPoperation Themes to the latest version beyond 1.1.9.
Stored cross-site scripting in CVE-2024-24803 refers to the vulnerability that allows attackers to inject malicious scripts that are then stored on the server.
CVE-2024-24803 affects all versions of the Ultra Companion plugin for WPoperation Themes up to and including version 1.1.9.
Yes, CVE-2024-24803 can compromise website security by allowing attackers to execute unauthorized scripts on users' browsers.