CVE-2024-32531: WordPress GuCherry Blog theme <= 1.1.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest themes GuCherry Blog allows Reflected XSS.This issue affects GuCherry Blog: from n/a through 1.1.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32531?
CVE-2024-32531 has been classified as a high-severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-32531?
To fix CVE-2024-32531, update the GuCherry Blog theme to version 1.1.9 or later.
What are the potential impacts of CVE-2024-32531?
CVE-2024-32531 can allow attackers to execute arbitrary JavaScript in the context of the victim's browser, leading to data theft or session hijacking.
Is CVE-2024-32531 remote exploitable?
Yes, CVE-2024-32531 is remotely exploitable, as it involves reflected XSS that requires user interaction with a crafted URL.
Which versions of GuCherry Blog are affected by CVE-2024-32531?
CVE-2024-32531 affects all versions of GuCherry Blog from n/a up to and including version 1.1.8.