First published: Sun Aug 18 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes Bold Timeline Lite allows Stored XSS.This issue affects Bold Timeline Lite: from n/a through 1.2.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Everest Timeline Lite | <=1.2.0 | |
WordPress Bold Timeline Lite | <=1.2.0 |
Update to 1.2.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43294 is classified as a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS).
To fix CVE-2024-43294, update the Bold Timeline Lite plugin to a version later than 1.2.0 where the vulnerability is addressed.
CVE-2024-43294 can facilitate stored Cross-site Scripting (XSS) attacks that allow attackers to execute malicious scripts in a user's browser.
CVE-2024-43294 affects all versions of Bold Timeline Lite up to and including version 1.2.0.
Anyone using Bold Themes' Bold Timeline Lite plugin version 1.2.0 or earlier on their WordPress site is affected by CVE-2024-43294.