CVE-2024-2888: WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.26.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2888?
CVE-2024-2888 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-2888?
To fix CVE-2024-2888, update BoldGrid Post and Page Builder to the latest version that addresses this vulnerability.
Which versions of BoldGrid Post and Page Builder are affected by CVE-2024-2888?
CVE-2024-2888 affects BoldGrid Post and Page Builder versions up to and including 1.26.2.
What kind of attack does CVE-2024-2888 allow?
CVE-2024-2888 allows attackers to execute stored cross-site scripting (XSS) attacks.
Who is the vendor of the affected software for CVE-2024-2888?
The vendor of the affected software for CVE-2024-2888 is BoldGrid.