CVE-2024-50411: WordPress WP Abstracts plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability
Published Oct 29, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.7.1.
Affected Software
1 affected component
Kevonadonis Wp Abstracts Wordpress<2.7.2
Remediation
Information
Update to 2.7.2 or a higher version.
Event History
Oct 29, 2024
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-50411?
CVE-2024-50411 is classified as a high severity vulnerability due to its potential for stored XSS attacks.
2
How do I fix CVE-2024-50411?
To mitigate CVE-2024-50411, upgrade WP Abstracts to version 2.7.2 or later.
3
What systems are affected by CVE-2024-50411?
CVE-2024-50411 affects all versions of WP Abstracts prior to 2.7.2.
4
What type of vulnerability is CVE-2024-50411?
CVE-2024-50411 is an Improper Neutralization of Input During Web Page Generation, commonly known as Cross-site Scripting (XSS).
5
What are the potential impacts of CVE-2024-50411?
The impact of CVE-2024-50411 includes the possibility of an attacker executing arbitrary scripts in the context of the user's browser.