CVE-2024-43970: WordPress SureCart plugin <= 2.29.3 - Reflected Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a through 2.29.3.
Affected Software
1 affected component
SureCart SureCart WordPress<2.29.4
Remediation
Information
Update to 2.29.4 or a higher version.
Event History
Sep 17, 2024
CVE Published
via MITRE·11:33 PM
Data Sourced
via MITRE·11:33 PM
RemedyDescriptionSeverityWeakness
Sep 18, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43970?
CVE-2024-43970 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-43970?
To fix CVE-2024-43970, update SureCart to version 2.29.4 or later.
3
What systems are affected by CVE-2024-43970?
CVE-2024-43970 affects SureCart versions from n/a through 2.29.3.
4
What type of vulnerability is CVE-2024-43970?
CVE-2024-43970 is an improper neutralization of input during web page generation vulnerability, specifically a reflected cross-site scripting (XSS) issue.
5
Are there any known exploits for CVE-2024-43970?
As of now, there are no publicly disclosed exploits for CVE-2024-43970, but it is advisable to remediate the issue promptly.