CVE-2024-32567: WordPress DirectoryPress plugin <= 3.6.7 - Reflected Cross Site Scripting (XSS) vulnerability
Published Apr 18, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress allows Reflected XSS.This issue affects DirectoryPress: from n/a through 3.6.7.
Affected Software
3 affected components
Designinvento DirectoryPress<=3.6.7
WordPress DirectoryPress<=3.6.7
Designinvento Directorypress Wordpress<3.6.8
Remediation
Information
Update to 3.6.8 or a higher version.
Event History
Apr 18, 2024
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32567?
CVE-2024-32567 has a medium severity due to the potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-32567?
To fix CVE-2024-32567, update DirectoryPress to version 3.6.8 or later.
3
What types of attacks does CVE-2024-32567 allow?
CVE-2024-32567 allows attackers to perform reflected cross-site scripting (XSS) attacks.
4
Which versions of DirectoryPress are affected by CVE-2024-32567?
CVE-2024-32567 affects all versions of DirectoryPress from n/a up to and including 3.6.7.
5
Is CVE-2024-32567 specific to WordPress?
Yes, CVE-2024-32567 specifically affects the DirectoryPress plugin for WordPress.