CVE-2024-35739: WordPress The Post Grid plugin <= 7.7.1 - Cross Site Scripting (XSS) vulnerability
Published Jun 8, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme The Post Grid the-post-grid.This issue affects The Post Grid: from n/a through <= 7.7.1.
Affected Software
1 affected component
RadiusTheme The Post Grid Wordpress<7.7.2
Remediation
Information
Update to 7.7.2 or a higher version.
Event History
Jun 8, 2024
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35739?
CVE-2024-35739 is classified as a medium severity vulnerability due to its ability to allow stored cross-site scripting (XSS).
2
How do I fix CVE-2024-35739?
To fix CVE-2024-35739, update The Post Grid plugin to version 7.7.2 or later.
3
What is stored XSS in the context of CVE-2024-35739?
Stored XSS in CVE-2024-35739 refers to an attacker being able to inject malicious scripts that are stored on the server and executed in the context of other users' browsers.
4
Which versions of The Post Grid are affected by CVE-2024-35739?
CVE-2024-35739 affects all versions of The Post Grid plugin prior to 7.7.2.
5
Is the vulnerability CVE-2024-35739 specific to a certain platform?
Yes, CVE-2024-35739 specifically affects the The Post Grid plugin for WordPress.