CVE-2024-37471: WordPress Woffice Core plugin <= 5.4.8 - Site Wide Reflected Cross Site Scripting (XSS) vulnerability
Published Jul 4, 2024
·Updated
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.
Affected Software
1 affected component
Xtendify Woffice Wordpress<5.4.9
Remediation
Information
Update to 5.4.9 or a higher version.
Event History
Jul 4, 2024
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37471?
CVE-2024-37471 is classified as a Cross Site Scripting (XSS) vulnerability that can allow attackers to execute malicious scripts on the affected system.
2
How do I fix CVE-2024-37471?
To fix CVE-2024-37471, it is recommended to update Woffice Core to version 5.4.9 or later.
3
Which versions of Woffice are affected by CVE-2024-37471?
CVE-2024-37471 affects all versions of Woffice Core from n/a up to and including 5.4.8.
4
What kind of attacks can CVE-2024-37471 enable?
CVE-2024-37471 can enable reflected XSS attacks, potentially compromising user sessions and sensitive information.
5
Who is responsible for addressing CVE-2024-37471?
Website administrators using the affected Woffice Core version are responsible for addressing CVE-2024-37471 by applying the necessary updates.