CVE-2024-35679: WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jun 8, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.12.0.
Affected Software
1 affected component
GiveWP GiveWP WordPress<3.12.1
Remediation
Information
Update to 3.12.1 or a higher version.
Event History
Jun 8, 2024
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35679?
CVE-2024-35679 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting.
2
How do I fix CVE-2024-35679?
To fix CVE-2024-35679, update the GiveWP plugin to version 3.12.1 or later.
3
Which versions are affected by CVE-2024-35679?
CVE-2024-35679 affects GiveWP versions from n/a through 3.12.0.
4
What type of vulnerability is CVE-2024-35679?
CVE-2024-35679 is a reflected cross-site scripting (XSS) vulnerability.
5
What impact does CVE-2024-35679 have?
CVE-2024-35679 can allow attackers to execute scripts in the context of the user's browser, potentially leading to data theft or session hijacking.