CVE-2024-43279: WordPress Newsletters plugin <= 4.9.8 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43279?
CVE-2024-43279 is classified as a high severity Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2024-43279?
To fix CVE-2024-43279, update the Tribulant Newsletters or WordPress Newsletters plugin to version 4.9.9 or later.
Which versions of the software are affected by CVE-2024-43279?
CVE-2024-43279 affects Tribulant Newsletters versions up to and including 4.9.8 and the WordPress Newsletters plugin versions up to and including 4.9.8.
What type of vulnerability is CVE-2024-43279?
CVE-2024-43279 is an Improper Neutralization of Input During Web Page Generation vulnerability that leads to Reflected XSS.
Is there a workaround for CVE-2024-43279?
Currently, the best approach for CVE-2024-43279 is to apply the security updates provided by the vendor as no reliable workaround is available.