CVE-2024-56274: WordPress Astra Widgets plugin <= 1.2.15 - Cross Site Scripting (XSS) vulnerability
Published Jan 7, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.15.
Affected Software
3 affected components
Brainstormforce Astra Widgets Wordpress<1.2.16
Brainstorm Force Astra Widgets<=1.2.15
WordPress Astra Widgets<=1.2.15
Remediation
Information
Update the WordPress Astra Widgets wordpress plugin to the latest available version (at least 1.2.16).
Event History
Jan 7, 2025
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56274?
CVE-2024-56274 is a critical Stored XSS vulnerability affecting Astra Widgets versions up to 1.2.15.
2
How do I fix CVE-2024-56274?
To fix CVE-2024-56274, update Astra Widgets to the latest version beyond 1.2.15.
3
What are the potential impacts of CVE-2024-56274?
Exploitation of CVE-2024-56274 can lead to unauthorized access and manipulation of user data through stored XSS attacks.
4
Which versions of Astra Widgets are affected by CVE-2024-56274?
CVE-2024-56274 affects all Astra Widgets versions from n/a up to and including 1.2.15.
5
Is CVE-2024-56274 specific to any environment?
CVE-2024-56274 is specifically related to the WordPress environment, impacting Astra Widgets used within it.