Reflected XSS Vulnerability in WP Compress - Image Optimizer [All-In-One]
CVE-2024-47384
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 October 2024
What is CVE-2024-47384?
A reflected XSS vulnerability exists in WP Compress β Image Optimizer, allowing malicious actors to exploit improperly neutralized input during web page generation. This flaw enables attackers to execute arbitrary scripts in the context of the user's browser, which can lead to sensitive information disclosure, session hijacking, or further attacks on the affected site. All versions from n/a to 6.20.13 are affected, necessitating immediate attention to address potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Compress β Image Optimizer [All-In-One] <= 6.20.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved