CVE-2024-37278: WordPress Cards for Beaver Builder plugin <= 1.1.4 - Cross Site Scripting (XSS) vulnerability
Published Jul 22, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pratik Chaskar Cards for Beaver Builder.This issue affects Cards for Beaver Builder: from n/a through 1.1.4.
Affected Software
1 affected component
Brainstormforce Cards For Beaver Builder Wordpress<1.1.5
Remediation
Information
Update to 1.1.5 or a higher version.
Event History
Jul 22, 2024
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37278?
CVE-2024-37278 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2024-37278?
To fix CVE-2024-37278, update the Cards for Beaver Builder plugin to version 1.1.5 or later.
3
What versions are affected by CVE-2024-37278?
CVE-2024-37278 affects Cards for Beaver Builder versions from n/a through 1.1.4.
4
What kind of vulnerability is CVE-2024-37278?
CVE-2024-37278 is an improper neutralization of input vulnerability leading to Cross-site Scripting (XSS).
5
Who is the vendor for the product affected by CVE-2024-37278?
The vendor for the affected product is Brainstorm Force.