CVE-2024-30520: WordPress Carousel Anything For WPBakery Page Builder plugin <= 2.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Carousel Anything For WPBakery Page Builder allows Stored XSS.This issue affects Carousel Anything For WPBakery Page Builder: from n/a through 2.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30520?
CVE-2024-30520 is classified with a medium severity level due to its potential for Stored XSS attacks.
How do I fix CVE-2024-30520?
To fix CVE-2024-30520, update the Carousel Anything For WPBakery Page Builder plugin to version 2.1 or higher.
What type of vulnerability is CVE-2024-30520?
CVE-2024-30520 is a Cross-site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Who is affected by CVE-2024-30520?
CVE-2024-30520 affects users of the Carousel Anything For WPBakery Page Builder plugin up to version 2.1.
What impact does CVE-2024-30520 have?
The impact of CVE-2024-30520 includes potential unauthorized access to user sessions and data through malicious script execution.