CVE-2024-49678: WordPress js paper theme <= 2.5.7 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jinwen js paper js-paper allows Reflected XSS.This issue affects js paper: from n/a through <= 2.5.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49678?
CVE-2024-49678 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS).
How do I fix CVE-2024-49678?
To mitigate CVE-2024-49678, it's recommended to upgrade to the latest version of the Jinwen js paper or WordPress js paper theme beyond version 2.5.7.
What type of vulnerability is CVE-2024-49678?
CVE-2024-49678 is an improper neutralization of input during web page generation leading to reflected cross-site scripting (XSS).
Which versions are affected by CVE-2024-49678?
CVE-2024-49678 affects Jinwen js paper versions up to 2.5.7 and the WordPress js paper theme up to version 2.5.7.
What are the potential impacts of CVE-2024-49678?
The potential impact of CVE-2024-49678 includes an attacker being able to execute arbitrary JavaScript in the context of a user's session.