VYPR
Medium severity5.9NVD Advisory· Published Apr 11, 2024· Updated Apr 23, 2026

CVE-2024-31929

CVE-2024-31929

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iain Poulson Intagrate Lite instagrate-to-wordpress.This issue affects Intagrate Lite: from n/a through <= 1.3.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Intagrate Lite ≤1.3.7 has a stored XSS vulnerability via improper input neutralization, allowing attackers to inject malicious scripts.

Vulnerability

Overview

CVE-2024-31929 is a reflected cross-site scripting (XSS) vulnerability in the Intagrate Lite plugin for WordPress, versions 1.3.7 and earlier. The root cause is improper neutralization of user-supplied input when generating web pages, which enables an attacker to inject arbitrary HTML and JavaScript code. This flaw is classified as a stored XSS, as the injected payload can persist and affect other users. [1][2]

Exploitation

Details

To exploit this vulnerability, an attacker must be able to submit crafted input to the affected plugin, typically through a field that is later displayed on a page. While the vulnerability is rated with a medium severity (CVSS 5.9) and exploitation may require a privileged user to perform an action such as clicking a malicious link, the attack can be initiated by any user with low privileges. Successful exploitation does not require the victim to be authenticated in all cases. [1][2]

Impact

If successfully exploited, an attacker can inject malicious scripts into the website, leading to actions such as redirecting visitors to malicious sites, displaying unwanted advertisements, or executing other HTML payloads. This can compromise the integrity and trustworthiness of the site, potentially affecting all visitors. The vulnerability has been flagged as one that could be used in mass-exploit campaigns targeting thousands of websites. [1][2]

Mitigation

The vendor has released version 1.3.8 which addresses the vulnerability. Users are strongly advised to update Intagrate Lite to version 1.3.8 or later. For those using Patchstack, enabling auto-updates for vulnerable plugins is recommended. No workarounds beyond updating have been confirmed. [1][2]

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.