CVE-2024-37239: WordPress Branda plugin <= 3.4.17 - Cross Site Scripting (XSS) vulnerability
Published Jul 22, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Branda branda-white-labeling.This issue affects Branda: from n/a through <= 3.4.17.
Affected Software
1 affected component
wpmudev Branda Wordpress<=3.4.18
Remediation
Information
Update to 3.4.18 or a higher version.
Event History
Jul 22, 2024
CVE Published
via MITRE·09:14 AM
Data Sourced
via MITRE·09:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37239?
CVE-2024-37239 is classified as a high-severity vulnerability due to its potential for Stored XSS attacks.
2
How do I fix CVE-2024-37239?
To mitigate CVE-2024-37239, update WPMU DEV Branda to version 3.4.18 or later.
3
What type of vulnerability is CVE-2024-37239?
CVE-2024-37239 is an Improper Neutralization of Input During Web Page Generation (XSS) vulnerability.
4
Which versions of Branda are affected by CVE-2024-37239?
CVE-2024-37239 affects all versions of Branda from n/a through 3.4.17.
5
What are the potential impacts of CVE-2024-37239?
CVE-2024-37239 can lead to stored arbitrary script execution within the application, compromising user data and session hijacking.