CVE-2024-47391

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 5, 2024
Updated: Jan 7, 2025
CWE ID 79

Summary

CVE-2024-47391 is an XSS (Cross-site Scripting) vulnerability affecting Bold Page Builder, a plugin used for website design. The flaw, which is classified as an improper neutralization of input during web page generation issue, enables attackers to inject malicious scripts and gain unauthorized access to user sessions. This vulnerability, present before version 5.1.1, poses a significant risk for websites that use the affected plugin. Successful exploitation of this flaw could lead to stolen user data, unauthorized actions, and other serious consequences. Users are strongly advised to update their Bold Page Builder plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share