First published: Mon Feb 12 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes.Com Buttons Shortcode and Widget allows Stored XSS.This issue affects Buttons Shortcode and Widget: from n/a through 1.16.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otwthemes Buttons Shortcode And Widget | <=1.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24930 has a high severity rating due to its ability to allow stored cross-site scripting (XSS) attacks.
To fix CVE-2024-24930, update the Buttons Shortcode and Widget plugin to version 1.17 or later.
CVE-2024-24930 affects all versions of the Buttons Shortcode and Widget plugin up to and including version 1.16.
CVE-2024-24930 allows stored cross-site scripting (XSS) attacks, which can lead to unauthorized access and data theft.
Users of the OTWthemes Buttons Shortcode and Widget plugin versions up to 1.16 on WordPress are affected by CVE-2024-24930.