CVE-2024-32690: WordPress RSS Feed Widget plugin <= 2.9.7 - Cross Site Scripting (XSS) vulnerability
Published Apr 22, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood RSS Feed Widget allows Stored XSS.This issue affects RSS Feed Widget: from n/a through 2.9.7.
Affected Software
1 affected component
Fahad Mahmood RSS Feed Widget<=2.9.7
Remediation
Information
Update to 2.9.8 or a higher version.
Event History
Apr 22, 2024
CVE Published
via MITRE·07:47 AM
Data Sourced
via MITRE·07:47 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32690?
CVE-2024-32690 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-32690?
To fix CVE-2024-32690, update the Fahad Mahmood RSS Feed Widget to version 2.9.8 or later.
3
What types of attacks does CVE-2024-32690 enable?
CVE-2024-32690 enables stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
4
Which versions are affected by CVE-2024-32690?
CVE-2024-32690 affects versions of the RSS Feed Widget from n/a up to and including 2.9.7.
5
Who is the vendor for CVE-2024-32690?
The vendor for CVE-2024-32690 is Fahad Mahmood, the developer of the RSS Feed Widget.