CVE-2024-29928: WordPress Advanced Sermons plugin <= 3.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a through 3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Advanced Sermonsto a version that resolves this vulnerability.Fixed in 3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29928?
CVE-2024-29928 is a reflected Cross-site Scripting (XSS) vulnerability with a critical severity rating.
How do I fix CVE-2024-29928?
To fix CVE-2024-29928, update the Advanced Sermons plugin to version 3.2 or later.
What software is affected by CVE-2024-29928?
CVE-2024-29928 affects the WP Codeus Advanced Sermons plugin versions up to 3.1.
What types of attacks can CVE-2024-29928 facilitate?
CVE-2024-29928 can facilitate reflected Cross-site Scripting (XSS) attacks.
What actions should I take if I cannot update to a fixed version for CVE-2024-29928?
If you cannot update, consider disabling the Advanced Sermons plugin until a fix can be applied to mitigate the risk from CVE-2024-29928.