Vulnerability warning
-
One of my client website uses the getwid plugin and its hosted in WPEngine. Security scan reported below vulnerability. kindly fix the same and provide the updated plugin.
Getwid has a known vulnerability that may be affecting this version.
– < 2.1.12
This plugin is closed. Please replace it with another.
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Global score: 6.4 / 10
Severity: Medium
[+] CVE-2024-5020
[+] Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
[+] WordPress Getwid – Gutenberg Blocks Plugin <= 2.0.11 is vulnerable to Cross Site Scripting (XSS)
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
The topic ‘Vulnerability warning’ is closed to new replies.