CVE-2024-31365: WordPress Post Type Builder (PTB) plugin < 2.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
Published Apr 9, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type Builder (PTB) allows Reflected XSS.This issue affects Post Type Builder (PTB): from n/a before 2.1.1.
Affected Software
2 affected components
Themify Post Type Builder<2.1.1
WordPress Post Type Builder<2.1.1
Remediation
Information
Update to 2.1.1 or a higher version.
Event History
Apr 9, 2024
CVE Published
via MITRE·07:14 AM
Data Sourced
via MITRE·07:14 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31365?
CVE-2024-31365 has a medium severity rating due to its potential for exploitation through reflected cross-site scripting.
2
How do I fix CVE-2024-31365?
To fix CVE-2024-31365, update Themify Post Type Builder to version 2.1.1 or later.
3
What software is affected by CVE-2024-31365?
CVE-2024-31365 affects Themify Post Type Builder and WordPress Post Type Builder versions prior to 2.1.1.
4
What type of vulnerability is CVE-2024-31365?
CVE-2024-31365 is classified as a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-31365 lead to data theft?
Yes, CVE-2024-31365 can potentially allow attackers to execute scripts in the user's browser, leading to data theft.