CVE-2024-43304: WordPress Cryptocurrency Widgets plugin <= 2.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Reflected XSS.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.8.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43304?
The severity of CVE-2024-43304 is considered high due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2024-43304?
To fix CVE-2024-43304, update the Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List to version 2.8.1 or later.
What is CVE-2024-43304?
CVE-2024-43304 is an improper neutralization of input during web page generation vulnerability leading to reflected XSS in the affected plugin.
Which versions are affected by CVE-2024-43304?
CVE-2024-43304 affects versions of the Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List from n/a up to and including 2.8.0.
Who is the vendor for CVE-2024-43304?
The vendor for CVE-2024-43304 is Cool Plugins, which develops the Cryptocurrency Widgets – Price Ticker & Coins List.