CVE-2024-32126: WordPress Navigation menu as dropdown Widget plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Navigation menu as Dropdown Widget navigation-menu-as-dropdown-widget.This issue affects Navigation menu as Dropdown Widget: from n/a through <= 1.3.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32126?
CVE-2024-32126 is considered to be a moderate severity vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2024-32126?
To fix CVE-2024-32126, update the Navigation menu as Dropdown Widget plugin to version 1.3.5 or later.
What is the impact of CVE-2024-32126?
The impact of CVE-2024-32126 includes the potential for attackers to inject malicious scripts that can lead to data theft or unauthorized actions within a user's session.
Which versions are affected by CVE-2024-32126?
CVE-2024-32126 affects versions of the Navigation menu as Dropdown Widget plugin from n/a through version 1.3.4.
Who is the vendor associated with CVE-2024-32126?
The vendor associated with CVE-2024-32126 is WordPress, specifically the Navigation menu as Dropdown Widget.