CVE-2024-34795: WordPress Tainacan plugin <= 0.21.3 - Cross Site Scripting (XSS) vulnerability
Published Jun 3, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.
Affected Software
3 affected components
Tainacan Tainacan Wordpress<0.21.4
Tainacan.Org Tainacan<=0.21.3
WordPress Tainacan plugin<=0.21.3
Remediation
Information
Update to 0.21.4 or a higher version.
Event History
Jun 3, 2024
CVE Published
via MITRE·10:44 AM
Data Sourced
via MITRE·10:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34795?
CVE-2024-34795 has a severity rating that indicates a significant risk due to stored Cross-site Scripting (XSS) vulnerabilities.
2
How do I fix CVE-2024-34795?
To fix CVE-2024-34795, update Tainacan to the latest version beyond 0.21.3 where the vulnerability is addressed.
3
What effect does CVE-2024-34795 have on my website?
CVE-2024-34795 can allow an attacker to exploit stored XSS vulnerabilities, potentially leading to unauthorized actions or data theft.
4
Which versions are affected by CVE-2024-34795?
CVE-2024-34795 affects Tainacan versions from n/a through 0.21.3.
5
Is the WordPress Tainacan plugin also affected by CVE-2024-34795?
Yes, the WordPress Tainacan plugin versions up to and including 0.21.3 are affected by CVE-2024-34795.