CVE-2024-39631: WordPress Contest Gallery plugin <= 23.1.2 - Cross Site Scripting (XSS) vulnerability
Published Aug 1, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.
Affected Software
1 affected component
contest-gallery Contest Gallery Wordpress<23.1.3
Remediation
Information
Update to 23.1.3 or a higher version.
Event History
Aug 1, 2024
CVE Published
via MITRE·10:27 PM
Data Sourced
via MITRE·10:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39631?
The severity of CVE-2024-39631 is classified as high due to its potential for stored Cross-site Scripting (XSS) attacks.
2
How do I fix CVE-2024-39631?
To fix CVE-2024-39631, update the Contest Gallery plugin to version 23.1.3 or later.
3
What software versions are affected by CVE-2024-39631?
CVE-2024-39631 affects Contest Gallery versions up to and including 23.1.2.
4
What type of vulnerability is CVE-2024-39631?
CVE-2024-39631 is a Cross-site Scripting (XSS) vulnerability caused by improper neutralization of input.
5
Can CVE-2024-39631 lead to data theft?
Yes, CVE-2024-39631 can lead to data theft as attackers may exploit XSS to steal user information or session tokens.