CVE-2024-29811: WordPress Radio Player plugin <= 2.0.73 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29811?
CVE-2024-29811 is classified as a high severity vulnerability due to its potential to enable Stored Cross-Site Scripting (XSS).
How do I fix CVE-2024-29811?
To mitigate CVE-2024-29811, update the SoftLab Radio Player or the WordPress Radio Player plugin to versions beyond 2.0.73 where the vulnerability is addressed.
Who is affected by CVE-2024-29811?
CVE-2024-29811 affects users of SoftLab Radio Player versions up to and including 2.0.73 and the WordPress Radio Player plugin versions up to and including 2.0.73.
What kind of attack is associated with CVE-2024-29811?
CVE-2024-29811 is associated with Stored Cross-Site Scripting (XSS) attacks, which can execute malicious scripts in the context of the user’s session.
Can CVE-2024-29811 lead to data leakage?
Yes, CVE-2024-29811 can lead to data leakage as it allows attackers to inject malicious scripts that can access sensitive user information.