CVE-2024-3368: All in One SEO < 4.6.1.1 - Contributor+ Stored XSS
The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3368?
CVE-2024-3368 is classified as a medium severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-3368?
To fix CVE-2024-3368, update the All in One SEO WordPress plugin to version 4.6.1.1 or higher.
Who is affected by CVE-2024-3368?
Users with the contributor role and above are affected by CVE-2024-3368 due to improper validation and escaping of post fields.
What type of vulnerability is CVE-2024-3368?
CVE-2024-3368 is a Stored Cross-Site Scripting vulnerability.
When was CVE-2024-3368 reported?
CVE-2024-3368 was reported prior to the release of version 4.6.1.1 of the All in One SEO WordPress plugin.