CVE-2024-56032: WordPress FV Descriptions plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jan 2, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Descriptions fv-descriptions allows Reflected XSS.This issue affects FV Descriptions: from n/a through <= 1.4.
Affected Software
1 affected component
FolioVision FV Descriptions<=1.4
Remediation
Information
No patched version is available. This plugin has been closed as of November 8, 2024 and is not available for download. This closure is temporary, pending a full review.
Event History
Jan 2, 2025
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56032?
CVE-2024-56032 is considered a high severity vulnerability due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-56032?
To fix CVE-2024-56032, you should update Foliovision FV Descriptions to version 1.5 or higher.
3
What type of vulnerability is CVE-2024-56032?
CVE-2024-56032 is classified as a Cross-site Scripting (XSS) vulnerability involving improper input neutralization.
4
Which products are affected by CVE-2024-56032?
CVE-2024-56032 affects Foliovision FV Descriptions versions up to 1.4.
5
Can CVE-2024-56032 be exploited through web applications?
Yes, CVE-2024-56032 can be exploited through web applications that utilize the affected FV Descriptions plugin.