CVE-2024-32550: WordPress BMI Adult & Kid Calculator plugin <= 1.2.1 - CSRF to XSS vulnerability
Published Apr 17, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in BMI Adult & Kid Calculator allows Stored XSS.This issue affects BMI Adult & Kid Calculator: from n/a through 1.2.1.
Affected Software
1 affected component
WordPress BMI Adult & Kid Calculator<=1.2.1
Remediation
Information
Update to 1.2.2 or a higher version.
Event History
Apr 17, 2024
CVE Published
via MITRE·08:09 AM
Data Sourced
via MITRE·08:09 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32550?
CVE-2024-32550 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to stored XSS attacks.
2
How do I fix CVE-2024-32550?
To fix CVE-2024-32550, update the BMI Adult & Kid Calculator and the WordPress BMI Adult & Kid Calculator plugin to the latest version.
3
Which versions of the BMI Adult & Kid Calculator are affected by CVE-2024-32550?
CVE-2024-32550 affects all versions of BMI Adult & Kid Calculator up to 1.2.1.
4
Does CVE-2024-32550 affect WordPress installations?
Yes, CVE-2024-32550 affects the WordPress BMI Adult & Kid Calculator plugin up to version 1.2.1.
5
What types of attacks can CVE-2024-32550 allow?
CVE-2024-32550 can allow attackers to exploit Cross-Site Request Forgery to execute stored XSS.