CVE-2024-56292: WordPress Email Reminders Plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerability
Published Jan 7, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Email Reminders email-reminders allows Stored XSS.This issue affects Email Reminders: from n/a through <= 2.0.5.
Affected Software
1 affected component
wpdevelop Email Reminders<=2.0.5
Remediation
Information
Update the WordPress Email Reminders wordpress plugin to the latest available version (at least 2.0.6).
Event History
Jan 7, 2025
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56292?
CVE-2024-56292 is considered a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-56292?
To fix CVE-2024-56292, you should update the Email Reminders plugin to version 2.0.6 or later.
3
What type of vulnerability is CVE-2024-56292?
CVE-2024-56292 is classified as a Cross-Site Scripting (XSS) vulnerability.
4
Which versions are affected by CVE-2024-56292?
CVE-2024-56292 affects all versions of the Email Reminders plugin up to and including 2.0.5.
5
Who is affected by CVE-2024-56292?
Users of the wpdevelop Email Reminders plugin running version 2.0.5 or earlier are affected by CVE-2024-56292.