CVE-2024-29099: WordPress Evergreen Content Poster plugin <= 1.4.1 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 19, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster allows Reflected XSS.This issue affects Evergreen Content Poster: from n/a through 1.4.1.
Affected Software
3 affected components
Evergreencontentposter Evergreen Content Poster Wordpress<1.4.2
Evergreen Content Poster<=1.4.1
WordPress Evergreen Content Poster<=1.4.1
Remediation
Information
Update to 1.4.2 or a higher version.
Event History
Mar 19, 2024
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29099?
CVE-2024-29099 is classified as a high-severity reflected Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-29099?
To mitigate CVE-2024-29099, upgrade Evergreen Content Poster to version 1.4.2 or later.
3
What software is affected by CVE-2024-29099?
CVE-2024-29099 affects Evergreen Content Poster versions up to and including 1.4.1.
4
What type of vulnerability is CVE-2024-29099?
CVE-2024-29099 is an improper neutralization of input during web page generation, resulting in a reflected XSS vulnerability.
5
Can CVE-2024-29099 allow malicious attacks?
Yes, CVE-2024-29099 can allow attackers to execute arbitrary scripts in the context of a user's browser, potentially leading to data theft.