First published: Sun Aug 18 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS.This issue affects Houzez: from n/a through 3.2.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Houzez | <=3.2.4 | |
Houzez | <=3.2.4 |
Update to 3.2.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43244 is considered a critical Cross-site Scripting (XSS) vulnerability affecting versions of Houzez up to 3.2.4.
To fix CVE-2024-43244, update the Houzez theme to the latest version that resolves the XSS issue.
The potential impacts of CVE-2024-43244 include unauthorized script execution, session hijacking, and data theft due to reflected XSS risks.
CVE-2024-43244 affects FaveThemes Houzez versions from n/a to 3.2.4.
CVE-2024-43244 may be present in any installation of Houzez up to version 3.2.4, depending on the specific conditions of the web page generation.