CVE-2024-56297: WordPress Highlight plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability
Published Jan 7, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Highlight highlight allows Stored XSS.This issue affects Highlight: from n/a through <= 2.0.2.
Affected Software
1 affected component
QuantumCloud Highlight (WordPress plugin)<=2.0.2
Remediation
Information
Update the WordPress Highlight wordpress plugin to the latest available version (at least 2.0.6).
Event History
Jan 7, 2025
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56297?
CVE-2024-56297 is classified as a high severity vulnerability due to its potential to allow stored Cross-site Scripting (XSS) attacks.
2
How do I fix CVE-2024-56297?
To fix CVE-2024-56297, update the dn88 Highlight or WordPress Highlight plugin to version 2.0.3 or later.
3
What types of attacks can CVE-2024-56297 facilitate?
CVE-2024-56297 can facilitate stored Cross-site Scripting attacks, allowing attackers to inject malicious scripts.
4
Which versions of Highlight are affected by CVE-2024-56297?
CVE-2024-56297 affects dn88 Highlight versions up to and including 2.0.2.
5
Is CVE-2024-56297 a remote or local vulnerability?
CVE-2024-56297 is a remote vulnerability, as it can be exploited over a network by an attacker.