CVE-2024-49300: WordPress Hero Menu plugin <= 1.16.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows Reflected XSS. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin hmenu allows Reflected XSS.This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through <= 1.16.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49300?
CVE-2024-49300 is classified as a reflected XSS vulnerability that poses a significant risk to users of the affected WordPress plugin.
How do I fix CVE-2024-49300?
To fix CVE-2024-49300, update the NotFound Hero Mega Menu - Responsive WordPress Menu Plugin to version 1.16.6 or later.
What are the consequences of CVE-2024-49300?
The consequences of CVE-2024-49300 include potential exposure to malicious scripts that can compromise user data and session information.
Which versions are affected by CVE-2024-49300?
CVE-2024-49300 affects all versions of the NotFound Hero Mega Menu - Responsive WordPress Menu Plugin from n/a up to and including version 1.16.5.
Is CVE-2024-49300 easy to exploit?
Yes, CVE-2024-49300 can be exploited relatively easily due to its nature as a reflected XSS vulnerability.