CVE-2024-29818: WordPress WP Poll Maker plugin <= 3.1 - Authenticated Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker allows Stored XSS.This issue affects WP Poll Maker: from n/a through 3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Poll Makerto a version that resolves this vulnerability.Fixed in 3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29818?
CVE-2024-29818 is a medium severity vulnerability involving stored cross-site scripting (XSS) in the WP Poll Maker plugin.
How do I fix CVE-2024-29818?
To fix CVE-2024-29818, update the WP Poll Maker plugin to the latest version beyond 3.1.
What versions of WP Poll Maker are affected by CVE-2024-29818?
CVE-2024-29818 affects WP Poll Maker versions up to and including 3.1.
What type of vulnerability is CVE-2024-29818?
CVE-2024-29818 is classified as a cross-site scripting (XSS) vulnerability.
Who is impacted by CVE-2024-29818?
Users of the WP Poll Maker plugin prior to version 3.2 are impacted by CVE-2024-29818.