CVE-2024-29143: WordPress Passwordless Login plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29143?
CVE-2024-29143 is a high severity vulnerability due to its exploitation potential for stored cross-site scripting.
How do I fix CVE-2024-29143?
To fix CVE-2024-29143, upgrade the Cozmoslabs Passwordless Login plugin to version 1.1.3 or later.
What kind of attack can CVE-2024-29143 lead to?
CVE-2024-29143 can lead to stored cross-site scripting attacks, allowing attackers to execute arbitrary scripts in the context of a user's session.
What versions are affected by CVE-2024-29143?
CVE-2024-29143 affects Cozmoslabs Passwordless Login and WordPress Passwordless Login versions up to 1.1.2.
Is CVE-2024-29143 a browser-specific vulnerability?
CVE-2024-29143 is not browser-specific as it exploits web applications regardless of the browser used.