CVE-2024-32545: WordPress Canva – Design beautiful blog graphics plugin <= 1.2.4 - Cross Site Scripting (XSS) vulnerability
Published Apr 17, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Canva Canva – Design beautiful blog graphics allows Reflected XSS.This issue affects Canva – Design beautiful blog graphics: from n/a through 1.2.4.
Affected Software
1 affected component
Canva Canva – Design beautiful blog graphics<=1.2.4
Event History
Apr 17, 2024
CVE Published
via MITRE·08:22 AM
Data Sourced
via MITRE·08:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32545?
CVE-2024-32545 is classified as a medium-severity vulnerability due to its potential for reflected cross-site scripting (XSS).
2
How do I fix CVE-2024-32545?
Fix CVE-2024-32545 by updating the Canva – Design beautiful blog graphics to version 1.2.5 or later.
3
What platforms are affected by CVE-2024-32545?
CVE-2024-32545 affects versions of Canva – Design beautiful blog graphics up to and including 1.2.4.
4
What type of vulnerability is CVE-2024-32545?
CVE-2024-32545 is a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-32545 affect my website?
Yes, if you are using the affected versions of Canva on your website, CVE-2024-32545 may pose a risk.