CVE-2024-47384

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One] allows Reflected XSS.This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.20.13.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpcompress:wp_compress:*:*:*:*:*:wordpress:*:*

History

11 Aug 2025, 15:05

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/wp-compress-image-optimizer/wordpress-wp-compress-plugin-6-20-13-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/wp-compress-image-optimizer/wordpress-wp-compress-plugin-6-20-13-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve - Third Party Advisory
First Time Wpcompress wp Compress
Wpcompress
CPE cpe:2.3:a:wpcompress:wp_compress:*:*:*:*:*:wordpress:*:*
Summary
  • (es) Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web (XSS o 'Cross-site Scripting') en WP Compress WP Compress – Image Optimizer [All-In-One] permite XSS reflejado. Este problema afecta a WP Compress – Image Optimizer [All-In-One]: desde n/a hasta 6.20.13.

05 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-05 15:15

Updated : 2025-08-11 15:05


NVD link : CVE-2024-47384

Mitre link : CVE-2024-47384

CVE.ORG link : CVE-2024-47384


JSON object : View

Products Affected

wpcompress

  • wp_compress
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')