CVE-2024-54344: WordPress WP Quick Shop plugin <= 1.3.1 - Reflected Cross Site Scripting (XSS) vulnerability
Published Dec 13, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Quick Shop wp-quick-shop allows Reflected XSS.This issue affects WP Quick Shop: from n/a through <= 1.3.1.
Affected Software
1 affected component
Fahad Mahmood WP Quick Shop<=1.3.1
Remediation
Information
Update the WordPress WP Quick Shop plugin to the latest available version (at least 1.3.2).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-54344?
CVE-2024-54344 is classified as a medium severity reflected Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-54344?
To fix CVE-2024-54344, upgrade the WP Quick Shop plugin to the latest version beyond 1.3.1.
3
What are the potential impacts of CVE-2024-54344?
CVE-2024-54344 can allow attackers to execute arbitrary JavaScript code in the context of a user's browser session.
4
Which versions of WP Quick Shop are affected by CVE-2024-54344?
CVE-2024-54344 affects WP Quick Shop versions from n/a through 1.3.1.
5
Who is the vendor for CVE-2024-54344?
The vendor for CVE-2024-54344 is Fahad Mahmood, the developer of the WP Quick Shop plugin.