PT-2024-34782 · Unknown · Awesome Shortcodes For Genesis

Soprobro

·

Published

2024-11-19

·

Updated

2024-11-23

·

CVE-2024-51638

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Awesome Shortcodes For Genesis versions 1.1.8 and earlier
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability that allows Stored XSS. This means an attacker could potentially trick a user into performing unintended actions on a web application, and also store malicious scripts that could be executed by other users. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For versions 1.1.8 and earlier, update the plugin to the latest version to safeguard your site. As a temporary workaround, consider restricting access to the plugin until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-51638

Affected Products

Awesome Shortcodes For Genesis