First published: Sun Oct 06 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Accordion accordions allows Stored XSS.This issue affects Accordion: from n/a through 2.2.99.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Tabs & Accordion | <=2.2.99 | |
WordPress Accordion | <=2.2.99 |
Update to 2.2.100 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47342 is classified as a high severity vulnerability due to the potential for stored Cross-site Scripting (XSS) attacks.
To mitigate CVE-2024-47342, update the PickPlugins Accordion plugin to version 2.3.0 or higher.
CVE-2024-47342 can allow attackers to execute malicious scripts in the context of users' browsers, compromising their data and session.
CVE-2024-47342 affects all versions of the PickPlugins Accordion plugin up to and including version 2.2.99.
While XSS vulnerabilities are common, CVE-2024-47342 is specific to the PickPlugins Accordion plugin and thus may not be widely recognized.