CVE-2024-51926: WordPress GreenCon plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability
Published Nov 19, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul GreenCon greencon allows Stored XSS.This issue affects GreenCon: from n/a through <= 1.0.1.
Affected Software
1 affected component
Wpsoul GreenCon<=1.0.1
Remediation
Information
Deactivate and delete.
Event History
Nov 19, 2024
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-51926?
CVE-2024-51926 has a high severity rating due to the potential for Stored XSS attacks.
2
How do I fix CVE-2024-51926?
To fix CVE-2024-51926, update the Wpsoul GreenCon plugin to version 1.0.2 or later.
3
What type of vulnerability is CVE-2024-51926?
CVE-2024-51926 is an Improper Neutralization of Input During Web Page Generation vulnerability, specifically a Stored Cross-site Scripting (XSS) issue.
4
Which versions are affected by CVE-2024-51926?
CVE-2024-51926 affects Wpsoul GreenCon versions up to and including 1.0.1.
5
What products are impacted by CVE-2024-51926?
CVE-2024-51926 impacts the Wpsoul GreenCon plugin and the WordPress GreenCon plugin.