CVE-2024-32801: WordPress Widget Post Slider plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin Widget Post Slider allows Stored XSS.This issue affects Widget Post Slider: from n/a through 1.3.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32801?
CVE-2024-32801 is classified as a Cross-site Scripting (XSS) vulnerability, which can lead to serious security risks including data theft.
How do I fix CVE-2024-32801?
To fix CVE-2024-32801, update the ShapedPlugin Widget Post Slider to the latest version beyond 1.3.5.
Which versions of Widget Post Slider are affected by CVE-2024-32801?
CVE-2024-32801 affects all versions of the ShapedPlugin Widget Post Slider up to and including 1.3.5.
Can CVE-2024-32801 lead to data breaches?
Yes, CVE-2024-32801 can lead to data breaches as it allows attackers to execute malicious scripts in a user's browser.
Is CVE-2024-32801 a stored XSS vulnerability?
Yes, CVE-2024-32801 is categorized as a stored XSS vulnerability which means the malicious script can be permanently stored on the server.