First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Premium Packages allows Reflected XSS.This issue affects Premium Packages: from n/a through 5.8.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
W3 Eden Premium Packages | <=5.8.2 | |
WordPress Premium Packages | <=5.8.2 |
Update to 5.8.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29924 has been categorized as a Cross-site Scripting (XSS) vulnerability, which can result in the exposure of sensitive user data.
To fix CVE-2024-29924, upgrade the W3 Eden Premium Packages to version 5.8.3 or later to mitigate the vulnerability.
CVE-2024-29924 affects all versions of W3 Eden Premium Packages up to and including 5.8.2.
CVE-2024-29924 exploits reflected Cross-site Scripting (XSS) vulnerabilities during web page generation.
Yes, CVE-2024-29924 specifically affects the W3 Eden Premium Packages used on WordPress sites.