CVE-2024-34767: WordPress ShopLentor plugin <= 2.8.7 - Cross Site Scripting (XSS) vulnerability
Published Jun 3, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes ShopLentor allows Stored XSS.This issue affects ShopLentor: from n/a through 2.8.7.
Affected Software
3 affected components
HasThemes ShopLentor<=2.8.7
WordPress ShopLentor<=2.8.7
HasThemes Shoplentor Wordpress<2.8.8
Remediation
Information
Update to 2.8.8 or a higher version.
Event History
Jun 3, 2024
CVE Published
via MITRE·11:36 AM
Data Sourced
via MITRE·11:36 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34767?
CVE-2024-34767 is considered a critical severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-34767?
To fix CVE-2024-34767, update HasThemes ShopLentor to version 2.8.8 or later.
3
What versions of ShopLentor are affected by CVE-2024-34767?
CVE-2024-34767 affects HasThemes ShopLentor versions up to and including 2.8.7.
4
What type of vulnerability is CVE-2024-34767?
CVE-2024-34767 is an improper neutralization of input vulnerability that allows for stored cross-site scripting (XSS).
5
Can CVE-2024-34767 be exploited remotely?
Yes, CVE-2024-34767 can be exploited remotely, allowing attackers to execute malicious scripts in the context of a user's browser.