CVE-2024-52477: WordPress Document & Data Automation plugin <= 1.6.1 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in docxpresso Document & Data Automation document-data-automation allows Stored XSS.This issue affects Document & Data Automation: from n/a through <= 1.6.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52477?
CVE-2024-52477 has a medium severity rating due to its potential for exploitation through Cross-Site Request Forgery leading to Stored XSS.
How do I fix CVE-2024-52477?
To fix CVE-2024-52477, users should upgrade No-nonsense Labs Document & Data Automation to version 1.6.2 or later.
What products are affected by CVE-2024-52477?
CVE-2024-52477 affects No-nonsense Labs Document & Data Automation and the corresponding WordPress Document & Data Automation plugin up to version 1.6.1.
What type of vulnerability is CVE-2024-52477?
CVE-2024-52477 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Stored XSS.
Is there a workaround for CVE-2024-52477?
A temporary workaround for CVE-2024-52477 is to disable the affected plugin until an update is applied.