CVE-2024-35653: WordPress Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin <= 45.8.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: from n/a through <= 45.8.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35653?
CVE-2024-35653 is classified as a medium severity vulnerability due to its potential for exploitation through stored cross-site scripting (XSS).
How do I fix CVE-2024-35653?
To fix CVE-2024-35653, update Visual Composer Website Builder to version 45.9.0 or later as it includes a patch for the vulnerability.
What type of vulnerability is CVE-2024-35653?
CVE-2024-35653 is identified as a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages.
Which versions of Visual Composer Website Builder are affected by CVE-2024-35653?
CVE-2024-35653 affects Visual Composer Website Builder versions prior to 45.9.0.
What are the consequences of exploiting CVE-2024-35653?
Exploiting CVE-2024-35653 can lead to unauthorized actions on behalf of users and exposure of sensitive information via injected scripts.