CVE-2024-32815: WordPress All-in-one Like Widget plugin <= 2.2.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters All-in-one Like Widget all-in-one-facebook-like-widget.This issue affects All-in-one Like Widget: from n/a through <= 2.2.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32815?
The severity of CVE-2024-32815 is classified as a medium risk due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-32815?
To fix CVE-2024-32815, update the All-in-one Like Widget plugin to a version above 2.2.7 to mitigate the stored XSS vulnerability.
What versions are affected by CVE-2024-32815?
CVE-2024-32815 affects versions of the All-in-one Like Widget plugin from the initial release up to 2.2.7.
What type of vulnerability is CVE-2024-32815?
CVE-2024-32815 is an improper neutralization of input during web page generation, specifically a stored cross-site scripting (XSS) vulnerability.
Who is the vendor of the affected software for CVE-2024-32815?
The vendor of the affected software for CVE-2024-32815 is Jeroen Peters, specifically for the All-in-one Like Widget.