CVE-2024-43124: WordPress Graphina plugin <= 1.8.10 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Iqonic Design Graphina allows Stored XSS.This issue affects Graphina: from n/a through 1.8.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43124?
CVE-2024-43124 is classified as a high severity stored XSS vulnerability affecting Iqonic Design Graphina up to version 1.8.10.
How do I fix CVE-2024-43124?
To fix CVE-2024-43124, update Iqonic Design Graphina to version 1.8.11 or later.
What impact does CVE-2024-43124 have on systems?
CVE-2024-43124 allows attackers to execute arbitrary scripts in the context of the user's browser, potentially leading to data theft or session hijacking.
Is CVE-2024-43124 exploitable remotely?
Yes, CVE-2024-43124 can be exploited remotely if an attacker can send malicious inputs that are stored and later rendered in the application.
Which versions of Iqonic Design Graphina are affected by CVE-2024-43124?
CVE-2024-43124 affects Iqonic Design Graphina versions from the initial release up to and including 1.8.10.