CVE-2024-37474: WordPress Newspack Ads plugin <= 1.47.1 - Cross Site Scripting (XSS) vulnerability
Published Jul 4, 2024
·Updated
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.
Affected Software
1 affected component
Automattic Newspack Ads Wordpress<1.47.2
Remediation
Information
Update to 1.47.2 or a higher version.
Event History
Jul 4, 2024
CVE Published
via MITRE·06:11 PM
Data Sourced
via MITRE·06:11 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37474?
CVE-2024-37474 has a high severity rating due to the potential for stored Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2024-37474?
To fix CVE-2024-37474, update the Automattic Newspack Ads plugin to version 1.47.2 or later.
3
Which versions of Newspack Ads are affected by CVE-2024-37474?
CVE-2024-37474 affects versions of Newspack Ads from n/a through 1.47.1.
4
What type of vulnerability is CVE-2024-37474?
CVE-2024-37474 is a Cross Site Scripting (XSS) vulnerability, specifically a stored XSS issue.
5
Who is affected by CVE-2024-37474?
Any users utilizing the affected versions of the Automattic Newspack Ads plugin in WordPress are vulnerable to CVE-2024-37474.