CVE-2024-45460: WordPress Flipping Cards plugin <= 1.30 - Cross Site Scripting (XSS) vulnerability
Published Sep 15, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manu225 Flipping Cards flipping-cards allows Stored XSS.This issue affects Flipping Cards: from n/a through <= 1.30.
Affected Software
1 affected component
Info-d-74 Flipping Cards Wordpress<1.31
Remediation
Information
Update to 1.31 or a higher version.
Event History
Sep 15, 2024
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45460?
CVE-2024-45460 is classified as a high-severity vulnerability due to the risk of stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-45460?
To mitigate CVE-2024-45460, upgrade the Flipping Cards plugin to version 1.31 or later.
3
What types of attacks are possible with CVE-2024-45460?
CVE-2024-45460 can lead to stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
4
Which versions of Flipping Cards are affected by CVE-2024-45460?
CVE-2024-45460 affects Flipping Cards versions up to 1.30.
5
Is user input involved in exploiting CVE-2024-45460?
Yes, CVE-2024-45460 exploits improper neutralization of user input during web page generation.