CVE-2024-43133: WordPress Themify Shortcodes plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability
Published Aug 12, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Shortcodes allows Stored XSS.This issue affects Themify Shortcodes: from n/a through 2.1.1.
Affected Software
3 affected components
Themify Themify Shortcodes<=2.1.1
WordPress Themify Shortcodes<=2.1.1
Themify Themify Shortcodes Wordpress<2.1.2
Remediation
Information
Update to 2.1.2 or a higher version.
Event History
Aug 12, 2024
CVE Published
via MITRE·10:28 PM
Data Sourced
via MITRE·10:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43133?
CVE-2024-43133 is classified as a high severity vulnerability due to the potential for stored Cross-site Scripting (XSS).
2
How do I fix CVE-2024-43133?
To fix CVE-2024-43133, update Themify Shortcodes to version 2.1.2 or later.
3
What type of vulnerability is CVE-2024-43133?
CVE-2024-43133 is an Improper Neutralization of Input During Web Page Generation vulnerability that allows for stored XSS.
4
Which software versions are affected by CVE-2024-43133?
CVE-2024-43133 affects Themify Shortcodes versions from n/a up to 2.1.1.
5
What impact does CVE-2024-43133 have on users?
CVE-2024-43133 can allow attackers to execute arbitrary scripts in users' browsers, potentially leading to data theft or session hijacking.