CVE-2024-37476: WordPress Newspack Campaigns plugin <= 2.31.1 - Cross Site Scripting (XSS) vulnerability
Published Jul 4, 2024
·Updated
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1.
Affected Software
1 affected component
Automattic Newspack Popups Wordpress<2.31.2
Remediation
Information
Update to 2.31.2 or a higher version.
Event History
Jul 4, 2024
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-37476?
CVE-2024-37476 has been classified as a high severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-37476?
To mitigate CVE-2024-37476, update the Newspack Campaigns plugin to version 2.31.2 or later.
3
What versions of Newspack Campaigns are affected by CVE-2024-37476?
CVE-2024-37476 affects all versions of Newspack Campaigns up to and including 2.31.1.
4
What type of vulnerability is CVE-2024-37476?
CVE-2024-37476 is identified as a Stored Cross Site Scripting (XSS) vulnerability.
5
Who is impacted by the CVE-2024-37476 vulnerability?
Users of the Automattic Newspack Campaigns plugin from versions n/a through 2.31.1 are impacted by CVE-2024-37476.