CVE-2024-29928: WordPress Advanced Sermons plugin <= 3.1 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 27, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a through 3.1.
Affected Software
2 affected components
WordPress Advanced Sermons<=3.1
Wpcodeus Advanced Sermons Wordpress<3.2
Remediation
Information
Update to 3.2 or a higher version.
Event History
Mar 27, 2024
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29928?
CVE-2024-29928 is a reflected Cross-site Scripting (XSS) vulnerability with a critical severity rating.
2
How do I fix CVE-2024-29928?
To fix CVE-2024-29928, update the Advanced Sermons plugin to version 3.2 or later.
3
What software is affected by CVE-2024-29928?
CVE-2024-29928 affects the WP Codeus Advanced Sermons plugin versions up to 3.1.
4
What types of attacks can CVE-2024-29928 facilitate?
CVE-2024-29928 can facilitate reflected Cross-site Scripting (XSS) attacks.
5
What actions should I take if I cannot update to a fixed version for CVE-2024-29928?
If you cannot update, consider disabling the Advanced Sermons plugin until a fix can be applied to mitigate the risk from CVE-2024-29928.