CVE-2024-47647
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2024-47647 is an XSS (Cross-Site Scripting) vulnerability affecting the Accordion & FAQ plugin, specifically the Helpie WordPress Accordion FAQ plugin, version n/a through 1.27. Malicious scripts can be stored and executed on affected websites, leading to potential unauthorized access or data theft when users visit the site. This issue, named Improper Neutralization of Input During Web Page Generation, enables attackers to inject malicious code into the plugin's accordion and FAQ components, putting websites and their visitors at risk. Users are advised to update the plugin to the latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.