CVE-2024-49630: WordPress WP Education for Elementor plugin <= 1.2.8 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems WP Education wp-education allows Stored XSS.This issue affects WP Education: from n/a through <= 1.2.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49630?
CVE-2024-49630 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-49630?
To fix CVE-2024-49630, update the WP Education plugin to version 1.2.9 or later.
What does CVE-2024-49630 affect?
CVE-2024-49630 affects the WP Education plugin for WordPress versions up to 1.2.8.
What is stored XSS in relation to CVE-2024-49630?
Stored XSS in the context of CVE-2024-49630 allows an attacker to inject malicious scripts that can be executed by users visiting the affected pages.
Can CVE-2024-49630 be exploited remotely?
Yes, CVE-2024-49630 can be exploited remotely, allowing attackers to execute scripts in the context of users accessing the vulnerable site.