CVE-2024-35765: WordPress Greenshift – animation and page builder blocks plugin <= 8.8.9.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Stored XSS.This issue affects Greenshift – animation and page builder blocks: from n/a through 8.8.9.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35765?
CVE-2024-35765 has a high severity rating due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-35765?
To fix CVE-2024-35765, update the Greenshift – animation and page builder blocks plugin to version 8.8.9.2 or later.
What types of applications are affected by CVE-2024-35765?
CVE-2024-35765 affects the Greenshift – animation and page builder blocks plugin used in WordPress installations.
What does stored XSS mean in the context of CVE-2024-35765?
Stored XSS, as highlighted in CVE-2024-35765, refers to a vulnerability where malicious scripts are permanently stored on the target server and executed when a user accesses the affected web page.
How can CVE-2024-35765 impact users?
If exploited, CVE-2024-35765 can lead to unauthorized actions being performed on behalf of users, data theft, or site defacement.