CVE-2024-30430: WordPress FluentCRM plugin <= 2.8.44 - Cross Site Scripting (XSS) vulnerability
Published Mar 29, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44.
Affected Software
3 affected components
WP Email Newsletter Team FluentCRM<=2.8.44
WordPress FluentCRM plugin<=2.8.44
WPManageNinja Fluentcrm Wordpress<2.8.45
Remediation
Information
Update to 2.8.45 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30430?
CVE-2024-30430 is a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS).
2
How do I fix CVE-2024-30430?
To fix CVE-2024-30430, upgrade Fluent CRM to version 2.8.45 or later immediately.
3
Which versions of FluentCRM are affected by CVE-2024-30430?
CVE-2024-30430 affects FluentCRM versions up to and including 2.8.44.
4
What is stored Cross-site Scripting (XSS) in relation to CVE-2024-30430?
Stored XSS in CVE-2024-30430 allows attackers to inject malicious scripts into web pages viewed by other users.
5
How can CVE-2024-30430 impact my WordPress site?
If exploited, CVE-2024-30430 can compromise user data, lead to account hijacking, and damage your site's reputation.