CVE-2024-44005: WordPress Greenshift plugin <= 9.3.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Stored XSS.This issue affects Greenshift: from n/a through <= 9.3.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44005?
CVE-2024-44005 has been classified as a medium severity vulnerability due to the potential for stored cross-site scripting (XSS).
How do I fix CVE-2024-44005?
To fix CVE-2024-44005, update the Wpsoul Greenshift – animation and page builder blocks plugin to version 9.4 or later.
Who is affected by CVE-2024-44005?
CVE-2024-44005 affects users of the Greenshift – animation and page builder blocks plugin versions up to and including 9.3.7.
What types of attacks can CVE-2024-44005 allow?
CVE-2024-44005 can allow attackers to execute stored XSS, potentially compromising user sessions or sensitive information.
What is Cross-site Scripting (XSS) in relation to CVE-2024-44005?
In the context of CVE-2024-44005, Cross-site Scripting (XSS) refers to the improper handling of user input that enables attackers to inject malicious scripts into web pages.