CVE-2024-29102: WordPress Extensions For CF7 plugin <= 3.0.6 - Unauthenticated Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Extensions For CF7 allows Stored XSS.This issue affects Extensions For CF7: from n/a through 3.0.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29102?
CVE-2024-29102 has a critical severity level due to its potential for stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-29102?
To fix CVE-2024-29102, update the HasThemes Extensions For CF7 plugin to version 3.0.7 or later.
Which versions of HasThemes Extensions For CF7 are affected by CVE-2024-29102?
CVE-2024-29102 affects all versions of HasThemes Extensions For CF7 up to and including version 3.0.6.
What type of vulnerability is CVE-2024-29102?
CVE-2024-29102 is classified as an Improper Neutralization of Input During Web Page Generation vulnerability, specifically allowing Cross-Site Scripting (XSS).
Is CVE-2024-29102 a risk for WordPress websites?
Yes, CVE-2024-29102 poses a risk to WordPress websites using the affected versions of the Extensions For CF7 plugin.