CVE-2024-35654: WordPress Responsive theme <= 5.0.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive allows Stored XSS.This issue affects Responsive: from n/a through 5.0.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35654?
CVE-2024-35654 is classified as a Medium severity XSS vulnerability affecting the CyberChimps Responsive theme.
How do I fix CVE-2024-35654?
To fix CVE-2024-35654, update the CyberChimps Responsive theme to the latest version beyond 5.0.3.
What causes CVE-2024-35654?
CVE-2024-35654 is caused by improper neutralization of input during web page generation, leading to stored cross-site scripting.
What versions of CyberChimps Responsive are affected by CVE-2024-35654?
CVE-2024-35654 affects all versions of CyberChimps Responsive up to and including 5.0.3.
Can CVE-2024-35654 lead to data theft?
Yes, CVE-2024-35654 can lead to data theft as it allows attackers to execute malicious scripts in the context of the user’s browser.