CVE-2024-49703: WordPress WpEvently plugin <= 4.2.5 - Cross Site Scripting (XSS) vulnerability
Published Oct 24, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress.This issue affects WpEvently: from n/a through <= 4.2.5.
Affected Software
1 affected component
magepeopleteam WpEvently<=4.2.5
Remediation
Information
Update to 4.2.6 or a higher version.
Event History
Oct 24, 2024
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-49703?
CVE-2024-49703 has a medium severity rating due to its potential for stored XSS attacks.
2
How do I fix CVE-2024-49703?
To address CVE-2024-49703, update the Event Manager for WooCommerce to the latest version beyond 4.2.5.
3
What systems are affected by CVE-2024-49703?
CVE-2024-49703 affects MagePeople Event Manager for WooCommerce and WordPress WpEvently up to version 4.2.5.
4
What type of vulnerability is CVE-2024-49703?
CVE-2024-49703 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
Is there a known exploit for CVE-2024-49703?
As of now, there are no specific publicly known exploits for CVE-2024-49703 reported.