First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molongui allows Stored XSS.This issue affects Molongui: from n/a through 4.7.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amitzy Molongui | <=4.7.7 | |
WordPress Molongui plugin | <=4.7.7 |
Update to 4.7.8 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29764 is classified as a medium severity vulnerability due to its potential for exploitation through stored cross-site scripting (XSS).
To fix CVE-2024-29764, update the Molongui software or WordPress Molongui plugin to a version above 4.7.7 that includes the necessary security patches.
CVE-2024-29764 affects all versions of Molongui up to and including 4.7.7.
CVE-2024-29764 can facilitate stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts that execute in users' browsers.
To assess if your site is vulnerable to CVE-2024-29764, check if it's using the affected versions of Molongui or WordPress Molongui plugin.