CVE-2024-35705: WordPress Block for Font Awesome plugin <= 1.4.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ciprian Popescu Block for Font Awesome allows Stored XSS.This issue affects Block for Font Awesome: from n/a through 1.4.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35705?
CVE-2024-35705 is classified as a medium severity vulnerability due to its potential for exploitation via stored XSS attacks.
How do I fix CVE-2024-35705?
To fix CVE-2024-35705, update the Block for Font Awesome plugin to version 1.4.5 or later.
What types of attacks are possible with CVE-2024-35705?
CVE-2024-35705 allows for stored cross-site scripting (XSS) attacks, which can be used to execute malicious scripts in the context of a user's browser.
Which versions of Block for Font Awesome are affected by CVE-2024-35705?
CVE-2024-35705 affects Block for Font Awesome versions prior to 1.4.5.
Can CVE-2024-35705 be exploited remotely?
Yes, CVE-2024-35705 can be exploited remotely by an attacker to inject malicious scripts into web pages served to users.