CVE-2024-9600: Ditty < 3.1.47 - Author+ Stored XSS
The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9600?
CVE-2024-9600 is classified as a medium severity vulnerability due to its potential for Stored Cross-Site Scripting attacks by high privilege users.
How do I fix CVE-2024-9600?
To fix CVE-2024-9600, update the Ditty WordPress plugin to version 3.1.47 or later.
Who is affected by CVE-2024-9600?
CVE-2024-9600 affects users of the Ditty WordPress plugin prior to version 3.1.47, particularly those with high privilege roles.
What type of attack does CVE-2024-9600 enable?
CVE-2024-9600 allows for Stored Cross-Site Scripting attacks, potentially allowing attackers to inject malicious scripts.
What versions of the Ditty WordPress plugin are vulnerable to CVE-2024-9600?
Versions of the Ditty WordPress plugin prior to 3.1.47 are vulnerable to CVE-2024-9600.