CVE-2024-51676: WordPress Delisho plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious Delisho dr-widgets-blocks allows DOM-Based XSS.This issue affects Delisho: from n/a through <= 1.0.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51676?
CVE-2024-51676 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting.
How do I fix CVE-2024-51676?
To fix CVE-2024-51676, update the WP Delicious Delisho plugin to version 1.0.7 or higher.
What type of vulnerability is CVE-2024-51676?
CVE-2024-51676 is an improper neutralization of input during web page generation, resulting in a reflected XSS vulnerability.
What versions are affected by CVE-2024-51676?
CVE-2024-51676 affects WP Delicious Delisho versions up to and including 1.0.6.
Can CVE-2024-51676 be exploited by remote attackers?
Yes, CVE-2024-51676 can be exploited by remote attackers to execute unauthorized scripts in the context of a victim's browser.