CVE-2024-29818: WordPress WP Poll Maker plugin <= 3.1 - Authenticated Cross Site Scripting (XSS) vulnerability
Published Mar 27, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker allows Stored XSS.This issue affects WP Poll Maker: from n/a through 3.1.
Affected Software
2 affected components
InfoTheme WP Poll Maker<=3.1
InfoTheme Wp Poll Maker Wordpress<3.4
Remediation
Information
Update to 3.4 or a higher version.
Event History
Mar 27, 2024
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29818?
CVE-2024-29818 is a medium severity vulnerability involving stored cross-site scripting (XSS) in the WP Poll Maker plugin.
2
How do I fix CVE-2024-29818?
To fix CVE-2024-29818, update the WP Poll Maker plugin to the latest version beyond 3.1.
3
What versions of WP Poll Maker are affected by CVE-2024-29818?
CVE-2024-29818 affects WP Poll Maker versions up to and including 3.1.
4
What type of vulnerability is CVE-2024-29818?
CVE-2024-29818 is classified as a cross-site scripting (XSS) vulnerability.
5
Who is impacted by CVE-2024-29818?
Users of the WP Poll Maker plugin prior to version 3.2 are impacted by CVE-2024-29818.