CVE-2024-34794: WordPress Tainacan plugin <= 0.21.3 - Cross Site Scripting (XSS) vulnerability
Published Jun 3, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.
Affected Software
3 affected components
Tainacan Tainacan Wordpress<0.21.4
Tainacan Tainacan<=0.21.3
WordPress Tainacan plugin<=0.21.3
Remediation
Information
Update to 0.21.4 or a higher version.
Event History
Jun 3, 2024
CVE Published
via MITRE·10:50 AM
Data Sourced
via MITRE·10:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34794?
CVE-2024-34794 is rated as a medium severity vulnerability due to its potential for reflected XSS attacks.
2
How do I fix CVE-2024-34794?
To fix CVE-2024-34794, update Tainacan to version 0.21.4 or later.
3
Who is affected by CVE-2024-34794?
CVE-2024-34794 affects Tainacan versions up to and including 0.21.3 and the Tainacan plugin for WordPress in the same version range.
4
What kind of attacks can CVE-2024-34794 facilitate?
CVE-2024-34794 can facilitate reflected cross-site scripting (XSS) attacks, potentially allowing an attacker to execute malicious scripts in a user's browser.
5
Is CVE-2024-34794 present in older versions of Tainacan?
Yes, CVE-2024-34794 is present in all versions of Tainacan up to and including 0.21.3.