CVE-2024-24881: WordPress WP SMS Plugin <= 6.5.2 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc allows Reflected XSS.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.5.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityFormsto a version that resolves this vulnerability.Fixed in 6.5.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24881?
CVE-2024-24881 has been classified as a high severity vulnerability due to its potential for exploitation through reflected cross-site scripting.
How do I fix CVE-2024-24881?
To fix CVE-2024-24881, update the WP SMS – Messaging & SMS Notification plugin to version 6.5.4 or later.
What type of vulnerability is CVE-2024-24881?
CVE-2024-24881 is a Reflected Cross-Site Scripting (XSS) vulnerability.
Which versions of WP SMS are affected by CVE-2024-24881?
CVE-2024-24881 affects WP SMS – Messaging & SMS Notification for WordPress versions prior to 6.5.4.
What impact could CVE-2024-24881 have on my website?
If exploited, CVE-2024-24881 could allow attackers to execute malicious scripts in the context of a user's session, potentially stealing sensitive data.