PT-2024-30906 · WordPress · Wp Travel

Sharanabasappa

·

Published

2024-10-06

·

Updated

2024-10-07

·

CVE-2024-44039

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Travel versions through 9.3.1
Description The issue involves Improper Neutralization of Input During Web Page Generation, which is also known as Cross-site Scripting (XSS). This problem allows for Stored XSS in WP Travel.
Recommendations For versions through 9.3.1, update to a version later than 9.3.1 to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-44039

Affected Products

Wp Travel