CVE-2024-27958: WordPress Visualizer plugin <= 3.10.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 17, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Reflected XSS.This issue affects Visualizer: from n/a through 3.10.5.
Affected Software
3 affected components
Themeisle Visualizer Wordpress<3.10.6
Themeisle Visualizer<=3.10.5
WordPress Visualizer<=3.10.5
Remediation
Information
Update to 3.10.6 or a higher version.
Event History
Mar 17, 2024
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27958?
CVE-2024-27958 has a medium severity rating as it allows reflected Cross-site Scripting (XSS) vulnerabilities.
2
How do I fix CVE-2024-27958?
To fix CVE-2024-27958, update the Themeisle Visualizer plugin to version 3.10.6 or later.
3
What versions are affected by CVE-2024-27958?
CVE-2024-27958 affects versions of Themeisle Visualizer from n/a through 3.10.5.
4
Can CVE-2024-27958 lead to data theft?
Yes, CVE-2024-27958 can potentially lead to data theft by exploiting reflected XSS to execute malicious scripts in a user's browser.
5
Is CVE-2024-27958 specific to any platform?
CVE-2024-27958 is specific to the WordPress platform, affecting the Visualizer plugin.