CVE-2024-37459: WordPress PayPlus Payment Gateway plugin <= 6.6.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PayPlus LTD PayPlus Payment Gateway allows Reflected XSS.This issue affects PayPlus Payment Gateway: from n/a through 6.6.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37459?
CVE-2024-37459 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2024-37459?
To mitigate CVE-2024-37459, you should update your PayPlus Payment Gateway to version 6.6.9 or later.
What type of vulnerability is CVE-2024-37459?
CVE-2024-37459 is an improper neutralization of input during web page generation, specifically a reflected cross-site scripting (XSS) vulnerability.
Which versions of PayPlus Payment Gateway are affected by CVE-2024-37459?
CVE-2024-37459 affects PayPlus Payment Gateway versions prior to 6.6.9.
What can attackers achieve with CVE-2024-37459?
Attackers exploiting CVE-2024-37459 can execute malicious scripts in the context of the user's browser, potentially leading to data theft or session hijacking.