CVE-2024-34770: WordPress Popup Maker WP plugin <= 1.3.6 - Cross Site Scripting (XSS) vulnerability
Published Jun 3, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker WP popup-maker-wp allows Stored XSS.This issue affects Popup Maker WP: from n/a through <= 1.3.6.
Affected Software
1 affected component
Popup Maker Popup Maker WP<=1.3.6
Event History
Jun 3, 2024
CVE Published
via MITRE·11:13 AM
Data Sourced
via MITRE·11:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34770?
CVE-2024-34770 is classified as a high severity vulnerability due to its Stored XSS impact.
2
How do I fix CVE-2024-34770?
To fix CVE-2024-34770, update Popup Maker WP to version 1.2.8 or later.
3
What type of vulnerability is CVE-2024-34770?
CVE-2024-34770 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Cross-site Scripting (XSS).
4
Which versions of Popup Maker are affected by CVE-2024-34770?
CVE-2024-34770 affects Popup Maker WP versions from n/a through 1.2.8.
5
Can CVE-2024-34770 lead to data breaches?
Yes, CVE-2024-34770 can lead to data breaches by allowing attackers to execute malicious scripts in users' browsers.