CVE-2024-44063: WordPress Happyforms plugin <= 1.26.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44063?
CVE-2024-44063 is classified as a critical vulnerability due to its potential to enable stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-44063?
To fix CVE-2024-44063, update Happyforms to version 1.26.1 or later, which addresses the vulnerability.
What software is affected by CVE-2024-44063?
CVE-2024-44063 affects Happyforms from any version up to, but not including, 1.26.1.
What type of vulnerability is CVE-2024-44063?
CVE-2024-44063 is an improper neutralization of input during web page generation, resulting in a stored cross-site scripting (XSS) vulnerability.
Can CVE-2024-44063 be exploited remotely?
Yes, CVE-2024-44063 can be exploited remotely by an attacker to execute malicious scripts in the context of a user's session.