CVE-2024-37495: WordPress Create by Mediavine plugin <= 1.9.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mischiefmarmot Create by Mediavine mediavine-create.This issue affects Create by Mediavine: from n/a through <= 1.9.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37495?
The severity of CVE-2024-37495 is high due to the potential for stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2024-37495?
To fix CVE-2024-37495, update Create by Mediavine to version 1.9.8 or later.
What kind of vulnerability is CVE-2024-37495?
CVE-2024-37495 is an improper neutralization of input during web page generation, leading to stored XSS vulnerabilities.
Which versions of Create by Mediavine are affected by CVE-2024-37495?
Versions of Create by Mediavine from n/a through 1.9.7 are affected by CVE-2024-37495.
What impact does CVE-2024-37495 have on users?
CVE-2024-37495 allows attackers to inject malicious scripts that can execute in the context of the user's browser, leading to potential data theft or session hijacking.