First published: Mon Aug 12 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins ComboBlocks allows Stored XSS.This issue affects ComboBlocks: from n/a through 2.2.86.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Combo Blocks | <=2.2.86 | |
WordPress ComboBlocks | <=2.2.86 |
Update to 2.2.87 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43155 is classified as a high severity vulnerability due to its potential for stored XSS attacks.
To fix CVE-2024-43155, you should update the PickPlugins ComboBlocks to version 2.2.87 or later.
CVE-2024-43155 allows attackers to execute malicious scripts in the context of a user’s browser, leading to data theft or manipulation.
CVE-2024-43155 affects ComboBlocks versions up to and including 2.2.86.
CVE-2024-43155 is a notable vulnerability in the WordPress ecosystem, particularly affecting users of the ComboBlocks plugin.