WordPress Plugin Vulnerable to Cross-site Scripting Attacks
CVE-2024-49695
5.4MEDIUM
What is CVE-2024-49695?
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus allows Stored XSS.This issue affects WP Flow Plus: from n/a through 5.2.3.
Affected Version(s)
WP Flow Plus <= 5.2.3