CVE-2024-43971: WordPress Sunshine Photo Cart plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43971?
CVE-2024-43971 is classified as a high severity vulnerability due to the potential for reflected cross-site scripting (XSS).
How do I fix CVE-2024-43971?
To fix CVE-2024-43971, update the Sunshine Photo Cart plugin to version 3.2.6 or later where the vulnerability is patched.
What version of Sunshine Photo Cart is impacted by CVE-2024-43971?
CVE-2024-43971 affects Sunshine Photo Cart versions prior to 3.2.6.
What type of vulnerability is CVE-2024-43971?
CVE-2024-43971 is an improper neutralization of input during web page generation, commonly known as a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2024-43971 be exploited remotely?
Yes, CVE-2024-43971 can be exploited remotely by an attacker to execute malicious scripts in the context of affected users.