CVE-2024-4749: WP eMember < 10.3.9 - Reflected XSS
The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4749?
CVE-2024-4749 is classified as a medium severity vulnerability due to its potential for exploitation through reflected cross-site scripting.
How do I fix CVE-2024-4749?
To fix CVE-2024-4749, update the WP eMember plugin to version 10.3.9 or later where the vulnerability is patched.
What impact does CVE-2024-4749 have on users?
CVE-2024-4749 can allow attackers to execute malicious scripts in the context of an authenticated user's session, potentially compromising their data.
Which versions of WP eMember are affected by CVE-2024-4749?
CVE-2024-4749 affects all versions of the WP eMember plugin prior to 10.3.9.
How can I verify if my site is vulnerable to CVE-2024-4749?
To verify if your site is vulnerable to CVE-2024-4749, check the version of the WP eMember plugin installed on your WordPress site.