CVE-2024-34811: WordPress WP SMS plugin <= 6.5.1 - Cross Site Scripting (XSS) vulnerability
Published May 13, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.
Affected Software
3 affected components
VeronaLabs Wp Sms Wordpress<6.5.2
VeronaLabs WP SMS<=6.5.1
WordPress WP SMS<=6.5.1
Remediation
Information
Update to 6.5.2 or a higher version.
Event History
May 13, 2024
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
RemedyDescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·03:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34811?
CVE-2024-34811 is classified as a Stored Cross-site Scripting (XSS) vulnerability in VeronaLabs WP SMS.
2
How do I fix CVE-2024-34811?
To fix CVE-2024-34811, update the WP SMS plugin to the latest version beyond 6.5.1.
3
Which versions are affected by CVE-2024-34811?
CVE-2024-34811 affects WP SMS versions from n/a up to and including 6.5.1.
4
What type of attack can CVE-2024-34811 facilitate?
CVE-2024-34811 can facilitate Stored XSS attacks that allow attackers to inject malicious scripts.
5
What are the potential consequences of CVE-2024-34811?
The potential consequences of CVE-2024-34811 include unauthorized access to users' sensitive data and the ability to manipulate session variables.