CVE-2024-43949: WordPress GHActivity plugin <= 2.0.0-alpha - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through 2.0.0-alpha.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43949?
CVE-2024-43949 is rated as a high severity vulnerability due to its potential for causing Stored XSS attacks.
How do I fix CVE-2024-43949?
To fix CVE-2024-43949, upgrade to a version of GHActivity that is not affected, such as any version beyond 2.0.0-alpha.
What software is affected by CVE-2024-43949?
CVE-2024-43949 affects Automattic GHActivity plugin versions from n/a through 2.0.0-alpha and 1.5.0 and below.
What is Stored XSS in the context of CVE-2024-43949?
Stored XSS refers to the vulnerability allowing an attacker to inject malicious scripts into pages that are viewed by other users, potentially leading to data theft or session hijacking.
Is CVE-2024-43949 exploit public?
Yes, it is likely that PoC (Proof of Concept) exploits for CVE-2024-43949 have been publicly discussed, making it important to apply security updates promptly.