First published: Fri Mar 15 2024(Updated: )
Cross Site Scripting (XSS) vulnerability in Joel Starnes postMash – custom post order allows Reflected XSS.This issue affects postMash – custom post order: from n/a through 1.2.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
postMash | <=1.2.0 | |
postMash | <=1.2.0 | |
WordPress | <=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27196 has a medium severity rating due to the potential for reflected cross-site scripting attacks.
To fix CVE-2024-27196, update the postMash – custom post order plugin to version 1.2.1 or higher.
CVE-2024-27196 affects versions of the postMash – custom post order plugin up to and including 1.2.0.
CVE-2024-27196 is a Cross Site Scripting (XSS) vulnerability that allows for reflected attacks.
Yes, if you are using an affected version of the postMash – custom post order plugin on your website, it can be exploited.