First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alordiel Dropdown Multisite selector allows Stored XSS.This issue affects Dropdown Multisite selector: from n/a through 0.9.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Alordiel Dropdown Multisite selector | <=0.9.2 | |
WordPress Dropdown Multisite selector | <=0.9.2 |
Update to 0.9.2.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29910 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2024-29910, update the Alordiel Dropdown Multisite selector to a version beyond 0.9.2.
CVE-2024-29910 affects Alordiel Dropdown Multisite selector and WordPress Dropdown Multisite selector versions up to and including 0.9.2.
CVE-2024-29910 is a cross-site scripting (XSS) vulnerability that allows stored attacks through improper input neutralization.
The potential consequences of CVE-2024-29910 include unauthorized access to sensitive user data and the execution of harmful scripts in the user's browser.