CVE-2024-32568: WordPress WP 2FA plugin <= 2.6.2 - Reflected Cross Site Scripting (XSS) vulnerability
Published Apr 18, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP 2FA wp-2fa.This issue affects WP 2FA: from n/a through <= 2.6.2.
Affected Software
3 affected components
Melapress WP 2FA<=2.6.2
WordPress WP 2FA<=2.6.2
Melapress Wp 2fa Wordpress<2.6.3
Remediation
Information
Update to 2.6.3 or a higher version.
Event History
Apr 18, 2024
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32568?
CVE-2024-32568 has been classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-32568?
To fix CVE-2024-32568, update the Melapress WP 2FA plugin to version 2.6.3 or later where the vulnerability has been patched.
3
What type of attack does CVE-2024-32568 allow?
CVE-2024-32568 allows attackers to perform reflected Cross-site Scripting (XSS) attacks.
4
Which versions of WP 2FA are affected by CVE-2024-32568?
CVE-2024-32568 affects all versions of WP 2FA from n/a up to and including version 2.6.2.
5
Who is affected by CVE-2024-32568?
Users of Melapress WP 2FA plugin, especially those using versions up to 2.6.2, are affected by CVE-2024-32568.