U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-2957

Change History

CVE Rejected by Wordfence 4/24/2024 12:15:08 PM

Action Type Old Value New Value

CVE Translated by Wordfence 4/24/2024 12:15:08 PM

Action Type Old Value New Value
Removed Translation
Title: Simple Ajax Chat – Add a Fast, Secure Chat Box para WordPress
Description: El complemento Simple Ajax Chat – Add a Fast, Secure Chat Box para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del campo de nombre en todas las versiones hasta 20240216 incluida debido a una sanitización de entrada y un escape de salida insuficientes. Esto hace posible que un atacante no autenticado inyecte scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada.

								
						

CVE Modified by Wordfence 4/24/2024 12:15:08 PM

Action Type Old Value New Value
Removed CVSS V3.1
Wordfence AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

								
						
Changed Description
The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field in all versions up to, and including, 20240216 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Rejected reason: **DUPLICATE*** Please use CVE-2024-1983 instead.
Removed Reference
Wordfence https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3040452%40simple-ajax-chat&new=3040452%40simple-ajax-chat&sfp_email=&sfph_mail=

								
						
Removed Reference
Wordfence https://www.wordfence.com/threat-intel/vulnerabilities/id/f67b5cd8-bae8-48ca-87d5-7445724791f6?source=cve