First published: Sun Mar 17 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Reflected XSS.This issue affects Visualizer: from n/a through 3.10.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Visualizer | <3.10.6 | |
WordPress Visualizer | <=3.10.5 | |
Visualizer Tables and Charts Manager for WordPress | <=3.10.5 |
Update to 3.10.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27958 has a medium severity rating as it allows reflected Cross-site Scripting (XSS) vulnerabilities.
To fix CVE-2024-27958, update the Themeisle Visualizer plugin to version 3.10.6 or later.
CVE-2024-27958 affects versions of Themeisle Visualizer from n/a through 3.10.5.
Yes, CVE-2024-27958 can potentially lead to data theft by exploiting reflected XSS to execute malicious scripts in a user's browser.
CVE-2024-27958 is specific to the WordPress platform, affecting the Visualizer plugin.