CVE-2024-32696: WordPress AI Infographic Maker OpenAI plugin <= 4.6.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Infographic Maker – iList allows Stored XSS.This issue affects Infographic Maker – iList: from n/a through 4.6.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32696?
CVE-2024-32696 has a medium severity rating due to its potential for allowing stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-32696?
To fix CVE-2024-32696, update the QuantumCloud Infographic Maker – iList to version 4.6.7 or later.
What types of attacks can CVE-2024-32696 enable?
CVE-2024-32696 can enable stored cross-site scripting (XSS) attacks, which may allow an attacker to execute arbitrary scripts in users' browsers.
Which versions of QuantumCloud Infographic Maker – iList are affected by CVE-2024-32696?
CVE-2024-32696 affects QuantumCloud Infographic Maker – iList versions up to and including 4.6.6.
Are any other products affected by CVE-2024-32696 besides Infographic Maker – iList?
Yes, the WordPress AI Infographic Maker OpenAI plugin versions up to and including 4.6.6 are also affected by CVE-2024-32696.