CVE-2024-43972: WordPress Page Builder: Pagelayer – Drag and Drop website builder plugin <= 1.8.7 - Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows Stored XSS.This issue affects PageLayer: from n/a through 1.8.7.
Affected Software
1 affected component
PageLayer Pagelayer WordPress<1.8.8
Remediation
Information
Update to 1.8.8 or a higher version.
Event History
Sep 17, 2024
CVE Published
via MITRE·11:30 PM
Data Sourced
via MITRE·11:30 PM
RemedyDescriptionSeverityWeakness
Sep 18, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43972?
The severity of CVE-2024-43972 is classified as high due to the potential for stored Cross-site Scripting attacks.
2
How do I fix CVE-2024-43972?
To fix CVE-2024-43972, upgrade PageLayer to version 1.8.8 or later immediately.
3
What types of attacks are possible with CVE-2024-43972?
CVE-2024-43972 allows attackers to execute stored Cross-site Scripting (XSS) attacks on affected users.
4
Which versions of PageLayer are affected by CVE-2024-43972?
CVE-2024-43972 affects PageLayer versions up to and including 1.8.7.
5
Can CVE-2024-43972 be exploited remotely?
Yes, CVE-2024-43972 can be exploited remotely if an attacker can inject malicious scripts into the affected web pages.