CVE-2024-24874: WordPress Polls CP plugin <= 1.0.71 - Content Injection vulnerability
Published May 17, 2024
·Updated
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.
Affected Software
2 affected components
CodePeople CP Polls>=n/a, <=1.0.71
WordPress Polls CP<=1.0.71
Remediation
Information
Update to 1.0.72 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:23 AM
Data Sourced
via MITRE·08:23 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-24874?
CVE-2024-24874 is considered a high severity vulnerability due to its potential for code injection.
2
How do I fix CVE-2024-24874?
To fix CVE-2024-24874, update the CodePeople CP Polls plugin to the latest version beyond 1.0.71.
3
What impacts does CVE-2024-24874 have on users?
CVE-2024-24874 can allow attackers to inject malicious code that may compromise user data and site functionality.
4
Is CVE-2024-24874 being actively exploited?
While there are no specific reports of active exploitation, the nature of the vulnerability makes it a potential target.
5
What software versions are affected by CVE-2024-24874?
CVE-2024-24874 affects CodePeople CP Polls from version n/a up to and including 1.0.71.