CVE-2024-37944: WordPress WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin <= 5.9.1 - Cross Site Scripting (XSS) vulnerability
Published Jul 20, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Travel Engine allows Stored XSS.This issue affects WP Travel Engine: from n/a through 5.9.1.
Affected Software
2 affected components
Wptravelengine Wp Travel Engine Wordpress<5.9.2
WordPress WP Travel Engine<=5.9.1
Remediation
Information
Update to 5.9.2 or a higher version.
Event History
Jul 20, 2024
CVE Published
via MITRE·08:52 AM
Data Sourced
via MITRE·08:52 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37944?
CVE-2024-37944 is classified as a high severity vulnerability due to its potential to allow stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-37944?
To fix CVE-2024-37944, update the WP Travel Engine plugin to version 5.9.2 or later.
3
What products are affected by CVE-2024-37944?
CVE-2024-37944 affects WP Travel Engine plugin versions up to and including 5.9.1.
4
What type of vulnerability is CVE-2024-37944?
CVE-2024-37944 is an improper neutralization of input during web page generation, leading to stored XSS attacks.
5
What are the potential impacts of CVE-2024-37944?
The potential impacts of CVE-2024-37944 include unauthorized access, data theft, or malicious content execution on affected sites.