CVE-2024-33916: WordPress CPO Companion plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability
Published May 3, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MachoThemes CPO Companion allows Stored XSS.This issue affects CPO Companion: from n/a through 1.1.0.
Affected Software
1 affected component
Machothemes CPO Companion<=1.1.0
Event History
May 3, 2024
CVE Published
via MITRE·07:18 AM
Data Sourced
via MITRE·07:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33916?
CVE-2024-33916 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2024-33916?
To fix CVE-2024-33916, update MachoThemes CPO Companion to version 1.1.1 or later.
3
What type of vulnerability is CVE-2024-33916?
CVE-2024-33916 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
4
Which versions of CPO Companion are affected by CVE-2024-33916?
CVE-2024-33916 affects CPO Companion versions up to and including 1.1.0.
5
What risks are associated with CVE-2024-33916?
If exploited, CVE-2024-33916 can allow attackers to execute malicious scripts in the context of the victim's browser.