CVE-2024-51647: WordPress Featured Posts Scroll plugin <= 1.25 - CSRF to Stored Cross Site Scripting (XSS) vulnerability
Published Nov 9, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll allows Stored XSS.This issue affects Featured Posts Scroll: from n/a through 1.25.
Affected Software
2 affected components
Chaser324 Featured Posts Scroll<=1.25
WordPress Featured Posts Scroll<=1.25
Event History
Nov 9, 2024
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-51647?
CVE-2024-51647 is classified as a medium severity vulnerability due to its potential for Stored XSS attacks.
2
How do I fix CVE-2024-51647?
To fix CVE-2024-51647, update the Chaser324 Featured Posts Scroll plugin to a version later than 1.25.
3
Who is affected by CVE-2024-51647?
CVE-2024-51647 affects all versions of Chaser324 Featured Posts Scroll up to and including 1.25.
4
What type of vulnerability is CVE-2024-51647?
CVE-2024-51647 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Stored XSS.
5
Can CVE-2024-51647 be exploited without user interaction?
Yes, CVE-2024-51647 can be exploited by an attacker without direct user interaction, making it particularly dangerous.