CVE-2024-37257: WordPress Permalink Manager Lite plugin <= 2.4.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jul 22, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.3.
Affected Software
1 affected component
Permalink Manager Lite Project Permalink Manager Lite Wordpress<2.4.3.4
Remediation
Information
Update to 2.4.3.4 or a higher version.
Event History
Jul 22, 2024
CVE Published
via MITRE·09:06 AM
Data Sourced
via MITRE·09:06 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37257?
CVE-2024-37257 has a medium severity rating due to its potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-37257?
To fix CVE-2024-37257, update the Permalink Manager Lite plugin to version 2.4.3.4 or later.
3
What software is affected by CVE-2024-37257?
CVE-2024-37257 affects Permalink Manager Lite versions from n/a up to and including 2.4.3.3.
4
What type of vulnerability is CVE-2024-37257?
CVE-2024-37257 is classified as a reflected cross-site scripting (XSS) vulnerability.
5
Who discovered CVE-2024-37257?
CVE-2024-37257 was identified by Maciej Bis.