CVE-2024-37447: WordPress PixelYourSite plugin <= 9.6.1.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager allows Stored XSS.This issue affects PixelYourSite – Your smart PIXEL (TAG) Manager: from n/a through 9.6.1.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37447?
CVE-2024-37447 has a critical severity level due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-37447?
To mitigate CVE-2024-37447, update PixelYourSite to version 9.6.2 or later where the vulnerability has been resolved.
What is the impact of CVE-2024-37447?
The impact of CVE-2024-37447 includes the ability for attackers to execute arbitrary JavaScript code in the context of users' browsers.
Which versions of PixelYourSite are affected by CVE-2024-37447?
CVE-2024-37447 affects PixelYourSite versions up to 9.6.1.1.
Can CVE-2024-37447 lead to data theft?
Yes, CVE-2024-37447 can lead to data theft through phishing attacks performed using the stored XSS vulnerability.