CVE-2024-3641: Newsletter Popup <= 1.2 - Unauthenticated Stored XSS
Published May 16, 2024
·Updated
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins
Affected Software
2 affected components
WordPress Newsletter Popup<=1.2
Mndpsingh287 Newsletter Popup Wordpress<=1.2
Event History
May 16, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-3641?
CVE-2024-3641 has a moderate severity rating due to its potential to allow Cross-Site Scripting attacks.
2
How do I fix CVE-2024-3641?
To fix CVE-2024-3641, update the Newsletter Popup WordPress plugin to version 1.3 or later.
3
Who is affected by CVE-2024-3641?
CVE-2024-3641 affects users running the Newsletter Popup plugin version 1.2 or earlier on WordPress.
4
What type of vulnerability is CVE-2024-3641?
CVE-2024-3641 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
Can unauthenticated users exploit CVE-2024-3641?
Yes, unauthenticated visitors can exploit CVE-2024-3641 to perform XSS attacks against admins.