CVE-2024-25592: WordPress Broken Link Checker plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerability
Published Mar 15, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Broken Link Checker allows Stored XSS.This issue affects Broken Link Checker: from n/a through 2.2.3.
Affected Software
3 affected components
wpmudev Broken Link Checker Wordpress<2.2.4
WPMU DEV Broken Link Checker<=2.2.3
WordPress Broken Link Checker<=2.2.3
Remediation
Information
Update to 2.2.4 or a higher version.
Event History
Mar 15, 2024
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25592?
CVE-2024-25592 has been classified as a critical severity vulnerability due to its potential for Stored XSS attacks.
2
How do I fix CVE-2024-25592?
To fix CVE-2024-25592, update the Broken Link Checker plugin to version 2.2.4 or later.
3
What does CVE-2024-25592 affect?
CVE-2024-25592 affects WPMU DEV Broken Link Checker versions up to and including 2.2.3.
4
What is the nature of the vulnerability in CVE-2024-25592?
CVE-2024-25592 is an Improper Neutralization of Input During Web Page Generation vulnerability, allowing for Cross-site Scripting (XSS).
5
Can CVE-2024-25592 be exploited remotely?
Yes, CVE-2024-25592 can be exploited remotely, potentially impacting users accessing compromised web pages.