CVE-2024-29123: WordPress Link Library plugin <= 7.6 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 19, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.
Affected Software
3 affected components
Yannick Lefebvre Link Library<=7.6
WordPress Link Library<=7.6
Ylefebvre Link Library Wordpress<7.6.1
Remediation
Information
Update to 7.6.1 or a higher version.
Event History
Mar 19, 2024
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29123?
CVE-2024-29123 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-29123?
To fix CVE-2024-29123, update the Yannick Lefebvre Link Library to version 7.7 or later.
3
Which versions of Link Library are affected by CVE-2024-29123?
CVE-2024-29123 affects all versions of Yannick Lefebvre Link Library up to and including 7.6.
4
What type of vulnerability is CVE-2024-29123?
CVE-2024-29123 is an improper neutralization of input during web page generation, specifically leading to reflected XSS.
5
Can CVE-2024-29123 be exploited?
Yes, CVE-2024-29123 can be exploited by attackers to inject malicious scripts into the web pages served by the affected Link Library.