CVE-2024-43938: WordPress Name Directory plugin <= 1.29.0 - Reflected Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.29.0.
Affected Software
1 affected component
Jeroen Peters Name Directory<=1.29.0
Remediation
Information
Update to 1.29.1 or a higher version.
Event History
Sep 17, 2024
CVE Published
via MITRE·10:43 PM
Data Sourced
via MITRE·10:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43938?
CVE-2024-43938 is considered a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-43938?
To fix CVE-2024-43938, you should upgrade the Jeroen Peters Name Directory to version 1.29.1 or later.
3
What are the affected versions of Jeroen Peters Name Directory for CVE-2024-43938?
CVE-2024-43938 affects Jeroen Peters Name Directory versions up to and including 1.29.0.
4
Can CVE-2024-43938 be exploited remotely?
Yes, CVE-2024-43938 can be exploited remotely through crafted web requests that trigger reflected XSS.
5
What type of vulnerability is CVE-2024-43938?
CVE-2024-43938 is classified as a reflected cross-site scripting (XSS) vulnerability.