First published: Mon Apr 15 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POEditor allows Stored XSS.This issue affects POEditor: from n/a through 0.9.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ht Editor | <=0.9.8 | |
WordPress POEditor plugin | <=0.9.8 |
Update to 0.9.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32453 is classified as a high-severity Stored Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2024-32453, upgrade POEditor to version 0.9.9 or later.
CVE-2024-32453 affects POEditor up to version 0.9.8 and the WordPress POEditor plugin up to version 0.9.8.
CVE-2024-32453 allows attackers to execute stored XSS attacks during web page generation.
The impact of CVE-2024-32453 on users includes potential unauthorized actions being taken on their behalf due to executed scripts.