CVE-2024-47384: WordPress WP Compress plugin <= 6.20.13 - Reflected Cross Site Scripting (XSS) vulnerability
Published Oct 5, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Reflected XSS.This issue affects WP Compress: from n/a through <= 6.20.13.
Affected Software
3 affected components
WP Compress Image Optimizer<=6.20.13
WordPress WP Compress<=6.20.13
Wpcompress Wp Compress Wordpress<6.21.01
Remediation
Information
Update to 6.21.01 or a higher version.
Event History
Oct 5, 2024
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47384?
The severity of CVE-2024-47384 is considered to be high due to its potential for reflected XSS attacks.
2
How do I fix CVE-2024-47384?
To fix CVE-2024-47384, update the WP Compress – Image Optimizer plugin to version 6.20.14 or later.
3
What type of vulnerability is CVE-2024-47384?
CVE-2024-47384 is classified as a Cross-site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2024-47384?
CVE-2024-47384 affects users of WP Compress – Image Optimizer versions prior to 6.20.14.
5
Can CVE-2024-47384 be exploited remotely?
Yes, CVE-2024-47384 can be exploited remotely by attackers through crafted web requests.