CVE-2024-5713: if-so < 1.8.0.4 - Reflected XSS
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $SERVER['REQUESTURI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5713?
CVE-2024-5713 has been classified as a medium severity vulnerability due to its potential for Reflected Cross-Site Scripting.
How do I fix CVE-2024-5713?
To fix CVE-2024-5713, you should update the If-So Dynamic Content Personalization plugin to version 1.8.0.4 or later.
What are the potential impacts of CVE-2024-5713?
The potential impacts of CVE-2024-5713 include the execution of malicious scripts in the context of the user’s browser, leading to data theft or session hijacking.
Which versions of the If-So Dynamic Content Personalization plugin are affected by CVE-2024-5713?
CVE-2024-5713 affects all versions of the If-So Dynamic Content Personalization plugin prior to 1.8.0.4.
What is the nature of the vulnerability described in CVE-2024-5713?
CVE-2024-5713 is a Reflected Cross-Site Scripting vulnerability caused by improper escaping of the $_SERVER['REQUEST_URI'] parameter.