CVE-2024-39656: WordPress Tin Canny Reporting for LearnDash plugin <= 4.3.0.7 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Tin Canny Reporting for LearnDash allows Reflected XSS.This issue affects Tin Canny Reporting for LearnDash: from n/a through 4.3.0.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39656?
CVE-2024-39656 has been classified as a reflected Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2024-39656?
To fix CVE-2024-39656, update the Uncanny Owl Tin Canny Reporting for LearnDash plugin to a version later than 4.3.0.7.
What software is affected by CVE-2024-39656?
The vulnerability affects Uncanny Owl Tin Canny Reporting for LearnDash versions up to and including 4.3.0.7.
Is CVE-2024-39656 an input validation issue?
Yes, CVE-2024-39656 is caused by improper neutralization of input during web page generation.
Can CVE-2024-39656 be exploited?
Yes, CVE-2024-39656 can be exploited to perform reflected XSS attacks on affected installations.