CVE-2024-3996: Post Grid, Post Carousel, & List Category Posts < 2.4.28 - Editor+ Stored XSS
The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3996?
CVE-2024-3996 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks on WordPress sites.
How do I fix CVE-2024-3996?
To fix CVE-2024-3996, update the Smart Post Show plugin to version 2.4.28 or later.
Who is affected by CVE-2024-3996?
Users of the Smart Post Show WordPress plugin prior to version 2.4.28 are affected by CVE-2024-3996.
What type of vulnerability is CVE-2024-3996?
CVE-2024-3996 is a Stored Cross-Site Scripting vulnerability.
What is the impact of CVE-2024-3996 on my WordPress site?
CVE-2024-3996 can allow high privilege users to execute arbitrary scripts on the site, potentially compromising its security.