CVE · Medium

CVE-2024-11277 — 404 Solution [404-solution] < 2.35.20

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11277 404 Solution [404-solution] < 2.35.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.35.20 2.35.20 2024-11-19

CVE-2024-11277

The 404 Solution plugin through version 2.35.19 contains a reflected cross-site scripting vulnerability caused by inadequate sanitization of URL parameters and lack of proper output encoding. Attackers who are not authenticated can inject malicious scripts into web pages that will execute when users interact with specially crafted links. This vulnerability affects all versions prior to 2.35.20 and requires social engineering to successfully exploit, as the attacker must convince a user to click a malicious link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.