CVE-2024-56257: WordPress Coins MarketCap plugin <= 5.5.8 - Cross Site Scripting (XSS) vulnerability
Published Jan 2, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolPlugins Coins MarketCap coins-marketcap allows DOM-Based XSS.This issue affects Coins MarketCap: from n/a through <= 5.5.8.
Affected Software
1 affected component
Coolplugins Coins MarketCap<=5.5.8
Remediation
Information
Update the WordPress Coins MarketCap plugin to the latest available version (at least 5.5.9).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:23 PM
Data Sourced
via MITRE·12:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56257?
CVE-2024-56257 has a medium severity rating due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2024-56257?
To fix CVE-2024-56257, update the CoolPlugins Coins MarketCap plugin to version 5.5.9 or later.
3
What versions are affected by CVE-2024-56257?
CVE-2024-56257 affects CoolPlugins Coins MarketCap from n/a through version 5.5.8.
4
Is CVE-2024-56257 present in other plugins?
Yes, CVE-2024-56257 also affects the WordPress Coins MarketCap plugin up to version 5.5.8.
5
What is the impact of CVE-2024-56257?
The impact of CVE-2024-56257 includes the possibility of executing arbitrary scripts in the user's browser, leading to potential data theft.