CVE-2024-47347: WordPress Chartify plugin <= 2.7.6 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Chartify chart-builder allows Reflected XSS.This issue affects Chartify: from n/a through <= 2.7.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47347?
CVE-2024-47347 has been identified as a critical reflected cross-site scripting (XSS) vulnerability affecting Chartify versions from n/a to 2.7.6.
How do I fix CVE-2024-47347?
To fix CVE-2024-47347, update the Chartify plugin to the latest version beyond 2.7.6.
What types of attacks are possible with CVE-2024-47347?
CVE-2024-47347 allows attackers to execute arbitrary JavaScript in the context of a user's session, potentially leading to data theft or unauthorized actions.
Who is affected by CVE-2024-47347?
CVE-2024-47347 affects users of Chart Builder Team's Chartify plugin, specifically versions from n/a up to 2.7.6.
Is CVE-2024-47347 specific to any platform?
Yes, CVE-2024-47347 is specific to the Chartify plugin used in WordPress.