CVE-2024-43227: WordPress BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability
Published Aug 12, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8.
Affected Software
2 affected components
WPDeveloper BetterDocs<=3.5.8
WPDeveloper Betterdocs Wordpress<3.5.9
Remediation
Information
Update to 3.5.9 or a higher version.
Event History
Aug 12, 2024
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43227?
CVE-2024-43227 is classified as a Stored XSS vulnerability, which can lead to significant security risks for affected users.
2
How do I fix CVE-2024-43227?
To mitigate CVE-2024-43227, update WPDeveloper BetterDocs to version 3.5.9 or later as per the vendor's recommendations.
3
What versions of BetterDocs are affected by CVE-2024-43227?
CVE-2024-43227 affects WPDeveloper BetterDocs from any version up to and including 3.5.8.
4
What kind of attack is enabled by CVE-2024-43227?
CVE-2024-43227 allows attackers to execute stored cross-site scripting (XSS) attacks on vulnerable installations.
5
Who is affected by CVE-2024-43227?
Users of WPDeveloper BetterDocs with versions up to 3.5.8 are vulnerable to CVE-2024-43227.