CVE-2024-3236: Easy Notify Lite < 1.1.33 - Contributor+ Stored XSS
The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3236?
CVE-2024-3236 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
Who is affected by CVE-2024-3236?
CVE-2024-3236 affects users of the Popup Builder WordPress plugin and Easy Notify Lite version prior to 1.1.33.
How do I fix CVE-2024-3236?
To fix CVE-2024-3236, update the Popup Builder and Easy Notify Lite plugins to version 1.1.33 or later.
What type of attack can occur due to CVE-2024-3236?
CVE-2024-3236 allows for Stored Cross-Site Scripting (XSS) attacks which can compromise user data and security.
What fields are vulnerable in CVE-2024-3236?
CVE-2024-3236 affects Notification fields that are not properly sanitized and escaped, leading to XSS vulnerabilities.