First published: Tue Jan 07 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.15.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Astra | <=1.2.15 | |
WordPress Astra Widgets | <=1.2.15 |
Update the WordPress Astra Widgets wordpress plugin to the latest available version (at least 1.2.16).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56274 is a critical Stored XSS vulnerability affecting Astra Widgets versions up to 1.2.15.
To fix CVE-2024-56274, update Astra Widgets to the latest version beyond 1.2.15.
Exploitation of CVE-2024-56274 can lead to unauthorized access and manipulation of user data through stored XSS attacks.
CVE-2024-56274 affects all Astra Widgets versions from n/a up to and including 1.2.15.
CVE-2024-56274 is specifically related to the WordPress environment, impacting Astra Widgets used within it.