CVE-2024-39648: WordPress Eventin plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability
Published Aug 1, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.
Affected Software
3 affected components
Themewinter Eventin<=4.0.5
WordPress Eventin<=4.0.5
Themewinter Eventin Wordpress<4.0.6
Remediation
Information
Update to 4.0.6 or a higher version.
Event History
Aug 1, 2024
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39648?
CVE-2024-39648 has a high severity rating due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-39648?
To fix CVE-2024-39648, update Themewinter Eventin to version 4.0.6 or later, where this vulnerability has been addressed.
3
Which versions of Eventin are affected by CVE-2024-39648?
CVE-2024-39648 affects all versions of Themewinter Eventin up to and including 4.0.5.
4
What type of vulnerability is CVE-2024-39648?
CVE-2024-39648 is classified as a stored cross-site scripting (XSS) vulnerability.
5
Who is impacted by CVE-2024-39648?
Users of Themewinter Eventin and WordPress Eventin plugins up to version 4.0.5 are impacted by CVE-2024-39648.