CVE-2024-50461: WordPress EmbedPress plugin <= 4.0.14 - Cross Site Scripting (XSS) vulnerability
Published Oct 28, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper EmbedPress embedpress allows Stored XSS.This issue affects EmbedPress: from n/a through <= 4.0.14.
Affected Software
1 affected component
WPDeveloper Embedpress Wordpress<4.1.0
Remediation
Information
Update to 4.1.0 or a higher version.
Event History
Oct 28, 2024
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 24, 58279
Event
via MITRE·08:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-50461?
The severity of CVE-2024-50461 is classified as high due to the potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-50461?
To fix CVE-2024-50461, update WPDeveloper EmbedPress to version 4.1.0 or later.
3
What causes the CVE-2024-50461 vulnerability?
CVE-2024-50461 is caused by improper neutralization of input during web page generation, which allows for the execution of malicious scripts.
4
What versions are affected by CVE-2024-50461?
CVE-2024-50461 affects WPDeveloper EmbedPress versions from n/a up to 4.0.14.
5
Who is impacted by CVE-2024-50461?
Users of WPDeveloper EmbedPress prior to version 4.1.0 are impacted by CVE-2024-50461.