CVE-2024-25597: WordPress Ultimate Reviews plugin <= 3.2.8 - Unauthenticated Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25597?
CVE-2024-25597 has a high severity rating due to its potential for allowing stored cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2024-25597?
To fix CVE-2024-25597, update the Ultimate Reviews plugin to version 3.2.9 or higher.
What versions are affected by CVE-2024-25597?
CVE-2024-25597 affects all versions of Ultimate Reviews from n/a through 3.2.8.
What is a stored XSS vulnerability in CVE-2024-25597?
Stored XSS vulnerability in CVE-2024-25597 allows attackers to inject malicious scripts that can be executed when other users view the affected web pages.
Who is impacted by CVE-2024-25597?
Users of the Ultimate Reviews plugin version 3.2.8 and below on WordPress are impacted by CVE-2024-25597.