Reflected XSS Vulnerability in The Ultimate WordPress Toolkit - WP Extended
CVE-2024-37259
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 July 2024
What is CVE-2024-37259?
The WP Extended The Ultimate WordPress Toolkit is susceptible to a reflected cross-site scripting (XSS) vulnerability. This occurs due to improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are executed in the browser of unsuspecting users. The vulnerability affects versions prior to 2.4.7, potentially compromising the security of websites utilizing this plugin. Ensuring proper input handling and updating to the latest version will mitigate these risks.
Affected Version(s)
The Ultimate WordPress Toolkit β WP Extended 0 <= 2.4.7