CVE-2024-49295: WordPress Simple Testimonials Showcase plugin <= 1.1.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Testimonials Showcase simple-testimonials-showcase allows Stored XSS.This issue affects Simple Testimonials Showcase: from n/a through <= 1.1.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49295?
The severity of CVE-2024-49295 is categorized as high due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2024-49295?
To fix CVE-2024-49295, update the Simple Testimonials Showcase plugin to the latest version beyond 1.1.6.
What versions are affected by CVE-2024-49295?
CVE-2024-49295 affects Simple Testimonials Showcase versions up to and including 1.1.6.
What are the potential impacts of CVE-2024-49295?
The potential impacts of CVE-2024-49295 include unauthorized script execution, data theft, and user session hijacking.
Is CVE-2024-49295 applicable to both PressTigers and WordPress?
Yes, CVE-2024-49295 is applicable to both the PressTigers and WordPress versions of the Simple Testimonials Showcase plugin.