CVE-2024-30441: WordPress Combo Blocks plugin <= 2.2.74 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 29, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid allows Reflected XSS.This issue affects Post Grid: from n/a through 2.2.74.
Affected Software
2 affected components
PickPlugins Post Grid<=2.2.74
Combo Blocks<=2.2.74
Remediation
Information
Update to 2.2.76 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30441?
CVE-2024-30441 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-30441?
To fix CVE-2024-30441, update the Post Grid to version 2.2.75 or later.
3
Which versions of Post Grid are affected by CVE-2024-30441?
CVE-2024-30441 affects PickPlugins Post Grid versions from n/a through 2.2.74.
4
What type of attack is possible with CVE-2024-30441?
CVE-2024-30441 allows attackers to perform reflected cross-site scripting (XSS) attacks.
5
Does CVE-2024-30441 affect other plugins or applications?
Yes, CVE-2024-30441 also affects the WordPress Combo Blocks plugin up to version 2.2.74.