CVE-2024-29095: WordPress Site Reviews plugin <= 6.11.6 - Cross Site Scripting (XSS) vulnerability
Published Mar 19, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews.This issue affects Site Reviews: from n/a through <= 6.11.6.
Affected Software
1 affected component
Gemini Labs Site Reviews<=6.11.6
Remediation
Information
Update to 6.11.7 or a higher version.
Event History
Mar 19, 2024
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Apr 1, 58713
Event
via FIRST·03:55 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-29095?
CVE-2024-29095 is classified as a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-29095?
To mitigate CVE-2024-29095, update the Paul Ryley Site Reviews plugin to version 6.11.7 or later.
3
What kind of attacks can CVE-2024-29095 facilitate?
CVE-2024-29095 can facilitate stored cross-site scripting attacks, allowing an attacker to execute malicious scripts in users' browsers.
4
Which versions of Site Reviews are affected by CVE-2024-29095?
CVE-2024-29095 affects Paul Ryley Site Reviews from version n/a through 6.11.6.
5
Who is the vendor for CVE-2024-29095?
The vendor for CVE-2024-29095 is Paul Ryley, and it is related to the Site Reviews product.