CVE-2024-50414: WordPress Button contact VR plugin <= 4.7.9.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Buttonizer Button contact VR button-contact-vr allows Stored XSS.This issue affects Button contact VR: from n/a through <= 4.7.9.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50414?
The severity of CVE-2024-50414 is classified as high due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-50414?
To fix CVE-2024-50414, update the Button contact VR plugin to the latest version above 4.7.9.1.
What is CVE-2024-50414?
CVE-2024-50414 is a vulnerability that involves improper neutralization of input during web page generation, allowing for stored cross-site scripting attacks.
Which versions of Button contact VR are affected by CVE-2024-50414?
Button contact VR versions from n/a up to and including 4.7.9.1 are affected by CVE-2024-50414.
What kind of attacks can CVE-2024-50414 lead to?
CVE-2024-50414 can lead to stored XSS attacks, potentially allowing attackers to execute malicious scripts on users' browsers.