CVE-2024-47297: WordPress Polls CP plugin <= 1.0.74 - Reflected Cross Site Scripting (XSS) vulnerability
Published Oct 6, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Polls cp-polls allows Reflected XSS.This issue affects CP Polls: from n/a through <= 1.0.74.
Affected Software
1 affected component
CodePeople CP Polls (cp-polls)<=1.0.74
Remediation
Information
Update to 1.0.75 or a higher version.
Event History
Oct 6, 2024
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47297?
CVE-2024-47297 is classified as a reflected XSS vulnerability affecting CodePeople CP Polls.
2
How do I fix CVE-2024-47297?
To fix CVE-2024-47297, update CodePeople CP Polls to version 1.0.75 or later.
3
What versions of CP Polls are affected by CVE-2024-47297?
CVE-2024-47297 affects CodePeople CP Polls from an unspecified version through 1.0.74.
4
Can CVE-2024-47297 affect my WordPress site using Polls CP plugin?
Yes, CVE-2024-47297 affects the Polls CP plugin for WordPress up to version 1.0.74.
5
What type of attack can exploit CVE-2024-47297?
CVE-2024-47297 can be exploited through cross-site scripting (XSS) attacks.