CVE-2024-43301: WordPress Fonts plugin <= 3.7.7 - Cross Site Request Forgery (CSRF) to Stored XSSvulnerability
Published Aug 26, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.
Affected Software
1 affected component
Fontsplugin Fonts Wordpress<3.7.8
Remediation
Information
Update to 3.7.8 or a higher version.
Event History
Aug 26, 2024
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43301?
CVE-2024-43301 is classified as a moderate severity vulnerability due to its potential for exploitation in Cross-Site Request Forgery leading to Stored XSS.
2
How do I fix CVE-2024-43301?
To remediate CVE-2024-43301, update the Fonts Plugin to version 3.7.8 or later.
3
What types of attacks can CVE-2024-43301 facilitate?
CVE-2024-43301 can facilitate Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cross-Site Scripting (XSS).
4
Which versions of Fonts Plugin are affected by CVE-2024-43301?
CVE-2024-43301 affects Fonts Plugin versions from n/a through 3.7.7.
5
Is CVE-2024-43301 exploitable by unauthenticated attackers?
Yes, CVE-2024-43301 can be exploited by unauthenticated attackers through CSRF.