CVE-2024-29097: WordPress User profile plugin <= 2.0.20 - Subscriber+ Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins User profile allows Stored XSS.This issue affects User profile: from n/a through 2.0.20.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29097?
CVE-2024-29097 has been classified as a high severity vulnerability due to its potential to enable stored cross-site scripting (XSS).
How do I fix CVE-2024-29097?
To fix CVE-2024-29097, update the PickPlugins User profile plugin to a version greater than 2.0.20 as soon as possible.
What type of vulnerability is CVE-2024-29097?
CVE-2024-29097 is classified as a Cross-site Scripting (XSS) vulnerability that involves improper neutralization of input during web page generation.
Which versions of the PickPlugins User profile are affected by CVE-2024-29097?
CVE-2024-29097 affects all versions of PickPlugins User profile from its initial release up to and including version 2.0.20.
Is my website at risk if I use the affected versions of PickPlugins User profile?
Yes, if your website is using PickPlugins User profile versions up to 2.0.20, it is at risk of exploitation through stored XSS attacks.