CVE-2024-37275: WordPress NextScripts plugin <= 4.4.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows DOM-Based XSS.This issue affects NextScripts: from n/a through <= 4.4.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37275?
CVE-2024-37275 has a moderate severity rating due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2024-37275?
To fix CVE-2024-37275, upgrade to NextScripts Social Networks Auto-Poster version 4.4.7 or later.
What type of vulnerability is CVE-2024-37275?
CVE-2024-37275 is classified as an Improper Neutralization of Input During Web Page Generation vulnerability, specifically a reflected XSS issue.
Which versions of NextScripts are affected by CVE-2024-37275?
CVE-2024-37275 affects all versions of NextScripts Social Networks Auto-Poster from n/a up to and including 4.4.6.
Can CVE-2024-37275 be exploited remotely?
Yes, CVE-2024-37275 can be exploited remotely by attackers through crafted URLs that execute XSS in the user's browser.