CVE-2024-37436: WordPress Uncanny Toolkit Pro for LearnDash plugin < 4.1.4.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Reflected XSS.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37436?
CVE-2024-37436 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-37436?
To address CVE-2024-37436, update Uncanny Toolkit Pro for LearnDash to version 4.1.4.1 or later.
What are the consequences of CVE-2024-37436?
Exploitation of CVE-2024-37436 could allow attackers to execute malicious scripts in the context of the user's browser.
Which versions of Uncanny Toolkit Pro for LearnDash are affected by CVE-2024-37436?
CVE-2024-37436 affects all versions of Uncanny Toolkit Pro for LearnDash prior to 4.1.4.1.
How can I tell if my site is vulnerable to CVE-2024-37436?
If you are using a version of Uncanny Toolkit Pro for LearnDash earlier than 4.1.4.1, your site is vulnerable to CVE-2024-37436.