CVE-2024-38700: WordPress WPCS – WordPress Currency Switcher Professional plugin <= 1.2.0.3 - Arbitrary Shortcode Execution vulnerability
Published Jul 12, 2024
·Updated
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in realmag777 WPCS allows Code Injection.This issue affects WPCS: from n/a through 1.2.0.3.
Affected Software
2 affected components
realmag777 WPCS<=1.2.0.3
WordPress Currency Switcher Professional<=1.2.0.3
Event History
Jul 12, 2024
CVE Published
via MITRE·02:05 PM
Data Sourced
via MITRE·02:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38700?
CVE-2024-38700 is classified as a critical vulnerability due to the potential for code injection.
2
How do I fix CVE-2024-38700?
To fix CVE-2024-38700, upgrade the WPCS plugin to a version later than 1.2.0.3.
3
Who is affected by CVE-2024-38700?
CVE-2024-38700 affects users of realmag777 WPCS and WordPress Currency Switcher Professional versions up to 1.2.0.3.
4
What type of vulnerability is CVE-2024-38700?
CVE-2024-38700 is an injection vulnerability due to improper neutralization of special elements in output.
5
Can CVE-2024-38700 lead to data breaches?
Yes, CVE-2024-38700 can potentially allow attackers to execute arbitrary code, leading to data breaches.